QuestionQ17

Network access control

Refer to the exhibit.

Question Image

A partial OT network is displayed.

You have configured VLANs on the FortiGate device to segment the OT network. The supervisor now wants to connect to the PLC from the Engineering Workstation.

How can access from the Engineering Workstation to the PLC be allowed?

  • A You must configure intra-switch-policy as explicit.
  • B You must configure intra-switch-policy as implicit.
  • C You must configure forward domain IDs.
  • D You must configure a layer 3 switch.
Explanation

Traffic from VLAN 30 to VLAN 20 must be controlled as traffic between switch members. With intra-switch-policy set to explicit, the traffic must match a firewall policy, so a policy can permit the Engineering Workstation-to-PLC connection while retaining VLAN segmentation. In implicit mode, traffic between switch members is allowed without requiring firewall policies.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!