Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE7_EFW-7.0 topic 1 question 12 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 12
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Refer to the exhibit, which shows a partial routing table.

Assuming all the appropriate firewall policies are configured, what two changes would an administrator need to make if they wanted to send traffic from a client directly connected to port3, to a server directly connected to port4? (Choose two.)

  • A. Configure route leaking between VRF 12 and VRF 21.
  • B. Disable auto-asic-offload as this is not supported between VRF instances.
  • C. Configure RIPv2 to exchange route information between the VRF instances.
  • D. Configure route leaking between port3 and port4.
  • E. Enable SNAT on the relevant firewall policies to prevent RPF check drops.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
accessmsc
1 month, 3 weeks ago
Selected Answer: AC
learn it in udemy
upvoted 2 times
...
mau_80
9 months ago
Selected Answer: AE
A -> you need to configure route leaking E -> net 10.1.0.0/24 overlaps, so SNAT can bypass the RPF check
upvoted 4 times
fortiexpertguy
6 months, 4 weeks ago
Hi mau_80, could you please provide a more detailed explanation of why there is an overlap with subnet 10.1.0.0/24? This subnet is directly connected in VRF=12 and is reachable via a static route in the VRF=21 route table. It has not been duplicated in the locally connected networks of both VRFs. Thank you in advance.
upvoted 1 times
...
...
certifi46
11 months, 1 week ago
Selected Answer: AE
A and E
upvoted 1 times
...
Quetchup
1 year ago
Selected Answer: AE
Enterprise_Firewall_7.0_Study_Guide-Online.pdf p 148, 159
upvoted 1 times
...
Seph1
1 year, 2 months ago
Selected Answer: AE
A & E seems correct: A - is correct - you need to configure VRF route leaking B - didn`t find anything to confirm this. C - Rip is not supported D - route leaking configuration is not on interfaces. E - sounds right.
upvoted 4 times
...
Nappel
1 year, 3 months ago
C is not correct: https://docs.fortinet.com/document/fortigate/7.0.9/administration-guide/509828/vrf-routing-support
upvoted 1 times
...
pcbbj
1 year, 3 months ago
Selected Answer: AE
RIP doesn't support VRF
upvoted 4 times
...
Hesoyam
1 year, 3 months ago
Selected Answer: AE
I think the answers are A and E because RIP is not supported in VRF.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...