QuestionQ16

Network Security Support Engineer

Refer to the exhibit.

Question Image

FortiGate is already configured with a firewall policy that permits all ICMP traffic to flow from port1 to port3.

Which change must the administrator make to ensure that the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?

  • A Enable asymmetric routing under config system settings.
  • B Modify the default gateway on the laptop from 10.1.0.2 to 10.2.0.2.
  • C A firewall policy that allows all ICMP traffic from port3 to port1.
  • D Change the configuration from strict RPF check mode to feasible RPF check mode.
Explanation

The ICMP reply follows an asymmetric path and reaches the FortiGate without a matching session for the corresponding echo request. Enabling asymmetric routing allows FortiGate to forward this traffic instead of dropping it as invalid. Fortinet documents that an ICMP packet received without the corresponding request passing through the FortiGate is blocked by default, and that asymmetric routing can be enabled under config system settings.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!