QuestionQ10

Stateful Firewall and Screen Options

Two interfaces are in ZoneA, and traffic passes between them without any configured policy. You want to control traffic between those two interfaces.

Which two actions will allow this?

Choose two
  • A Configure interzone blocking on ZoneA and create a policy in that zone to control the traffic.
  • B Configure intrazone blocking on ZoneA and create a policy in that zone to control the traffic.
  • C Move one of the interfaces to a different zone and create an interzone policy to control the traffic.
  • D Move one of the interfaces to a different zone and create an intrazone policy to control the traffic.
Explanation

FortiGate permits traffic between interfaces in the same zone by default. Enabling intra-zone blocking creates a default-deny posture, so an explicit policy within that zone can selectively allow and control the traffic. Moving one interface to a separate zone makes the traffic interzone, which is controlled by an interzone policy.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!