QuestionQ8

System Configuration

An organization has an existing FortiGate deployed as a data center firewall (DCFW) that sends inbound files to FortiSandbox for inline scanning. Following a network redesign, traffic between the FortiSandbox and the DCFW now traverses an intermediate firewall. Inline scanning no longer functions.

When reviewing the intermediate firewall configuration, you find that it allows traffic on TCP/3389, UDP/53, and TCP/443.

What must be changed for the integration to function?

  • A FortiGate must be able to access FortiSandbox on TCP/4443.
  • B FortiGate must be able to access FortiSandbox on TCP/8890.
  • C FortiGate must be able to access FortiSandbox on UDP/8888.
  • D FortiGate must be able to access FortiSandbox on UDP/1344.
Explanation

FortiGate inline scanning requires the FortiSandbox appliance to be reachable on TCP/4443. The intermediate firewall must permit FortiGate-to-FortiSandbox traffic on that port; TCP/443 does not provide the required inline-scanning service.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!