B is correct -> security guide 6.4 p163
C is correct
D is incorrect : As soon as a VIP or DNAT rule is created, no need for IPV4 policy. It is implicitely allowed. We can block trafic by adding IPV4 policy
B is wrong
If NGFW mode is policy-based, then it is assumed that central-nat (specifically SNAT) is enabled implicitly.
From GUI:
Got to System -> Settings, under 'Inspection Mode' select 'Flow-based and under 'NGFW Mode' select 'Profil-based'.
From CLI.
# Config sys setting
set central-nat disable
end
https://kb.fortinet.com/kb/documentLink.do?externalID=FD49932
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
MEDO162
3 years, 11 months agoAOC
4 years agobwman
4 years, 1 month agoNetStef
4 years, 1 month agogordonF
4 years, 2 months agopetrus28
4 years, 2 months agopollyy
4 years, 2 months agopollyy
4 years, 2 months agoJay1982
4 years, 3 months agoJay1982
4 years, 3 months agopetrus28
4 years, 2 months ago