QuestionQ23

Network Security Support Engineer

Which two conditions can cause iprope_in_check() check failed, drop to appear when using debug flow?

Choose two
  • A Packet was dropped because of policy route misconfiguration.
  • B Packet was dropped because of traffic shaping.
  • C Trusted host list misconfiguration.
  • D VIP or IP pool misconfiguration.
Explanation

A trusted-host configuration that excludes the packet’s source address causes remote-management traffic to fail the local-in check. Also, using a static-route gateway address in a VIP or IP-pool configuration makes FortiGate identify that gateway as a local IP address and drop the traffic with this message. Fortinet troubleshooting guidance

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!