Creado por Erik Vasquez
hace casi 3 años
|
||
Refer to the exhibit, which contains a Performance SLA configuration.
An administrator has configured a performance SLA on FortiGate, which failed to generate any traffic.
Why is FortiGate not generating any traffic for the performance SLA?
Refer to the exhibit
In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output as shown in the exhibit.
What should the administrator do next to troubleshoot the problem?
Refer to the exhibit to view the application control profile. Users who use Apple FaceTime video conferences are unable to set up meetings.
In this scenario, which statement is true?
Refer to the exhibit.
Refer to the exhibit to view the firewall policy. Which statement is correct if well-known viruses are not being blocked?
Refer to the exhibit, which contains a session diagnostic output.
Refer to the exhibit. The exhibit shows proxy policies and proxy addresses, the authentication rule and authentication scheme, users, and firewall address.
An explicit web proxy is configured for subnet range 10.0.1.0/24 with three explicit web proxy policies.
The authentication rule is configured to authenticate HTTP requests for subnet range 10.0.1.0/24 with a form-based authentication scheme for the FortiGate local user database. Users will be prompted for authentication. How
will FortiGate process the traffic when the HTTP request comes from a machine with the source IP 10.0.1.10 to the destination http://www.fortinet.com? (
The exhibit shows the configuration for the SD-WAN member, Performance SLA and SD-WAN Rule, as well as the output of diagnose sys virtual wan link health-check.
Which interface will be selected as an outgoing interface?
Refer to the exhibit.
Review the Intrusion Prevention System (IPS) profile signature settings.
Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
The exhibit contains a network diagram, firewall policies, and a firewall address object configuration.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-user2. Remote-user2 is still able to access Webserver. Which
two changes can the administrator make to deny Webserver access for Remote-User2?
Based on the output shown in the exhibit, which two statements are correct?
Given the interfaces shown in the exhibit, which two statements are true?
Based on the raw logs shown in the exhibit, which statement is correct?
Which statement is correct if a user is unable to receive a block replacement message when downloading an infected file for the first time?
Based on the raw log, which two statements are correct?
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?
The SSL VPN connection fails when a user attempts to connect to it.
What should the user do to successfully connect to SSL VPN?
An administrator created a static route for Amazon Web Services.
What CLI command must the administrator use to view the route?
The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
Why did FortiGate drop the packet?
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices
to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up?
The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
Which two statements are true?
The exhibit contains a network interface configuration, firewall policies, and a CLI console configuration.
How will FortiGate handle user authentication for traffic that arrives on the LAN interface?