QuestionQ28

Network Security

Refer to the exhibit.

Question Image

Which statement about the packet debug flow output is correct?

  • A The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • B The packet size exceeded the outgoing interface MTU.
  • C The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • D The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
Explanation

In FortiGate flow debugging, Denied by quota check indicates that a traffic shaper session quota was reached. The per-IP traffic shaper limits concurrent sessions for the source IP address, so exceeding the configured maximum for 10.1.10.1 causes the packet to be dropped.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!