QuestionQ39

Network access control

Refer to the exhibits.

Question Image

Question Image

Question Image

The HR and SALES endpoints reside on the same VLAN and cannot ping one another.

What configuration must be changed to permit ping traffic?

  • A Enable ICMP snooping on the interface.
  • B Proxy ARP should be configured on FortiGate.
  • C Client-to-client traffic is allowed only at layer 2.
  • D Enable NAT on the firewall policy.
Explanation

Hosts in the same VLAN normally communicate directly at Layer 2. Enabling Block intra-VLAN traffic isolates same-VLAN clients; allowing client-to-client traffic at Layer 2 removes that isolation and permits ICMP. NAT and Proxy ARP are not required for same-subnet host communication.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!