Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE7_EFW-7.0 topic 1 question 9 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 9
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Refer to the exhibit, which shows a session table entry.

Which statement about FortiGate behavior relating to this session is true?

  • A. FortiGate redirected the client to the captive portal to authenticate, so that a correct policy match could be made.
  • B. FortiGate forwarded this session without any inspection.
  • C. FortiGate is performing security profile inspection using the CPU.
  • D. FortiGate applied only IPS inspection to this session.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Seph1
Highly Voted 1 year, 2 months ago
Selected Answer: C
C - is correct. url_cat=41 - web filter is on. NPU is 0/0 so only CPU is working
upvoted 5 times
...
mikerss
Most Recent 4 months, 1 week ago
Selected Answer: C
C is the correct answer. This article explains that inspection is being done because proto_state=11 https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-session-table-information/ta-p/196988?externalID=FD30042 proto_state: state of the session (depending on protocol) For TCP, the first number (from left to right) is related to the server-side state and is 0 when the session is not subject to any inspection (flow or proxy). If flow or proxy inspection is done, then the first digit will be different from 0. The second digit is the client-side state. The table above correlates the second-digit value with the different TCP session states. For example, when FortiGate receives the SYN packet, the second digit is 2. It changes to 3 when the SYN/ACK packet is received. After the three-way handshake, the state value changes to 1. This article explains that traffic is not offloaded to npu: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Is-a-session-offloaded-Hardware-acceleration/ta-p/193373 If traffic is not offloaded on any direction, it would appear as follows: offload=0/0.
upvoted 1 times
...
BlackDealth
5 months, 3 weeks ago
C is correct In the output from the diagnose sys session list command on a FortiGate device, the offload=0/0 information under the npu info section signifies that the session in question is not being offloaded to a Network Processing Unit (NPU), but is instead being handled by the Central Processing Unit (CPU). Here's a breakdown of what this information means: offload=0/0: The two numbers represent the offload state for both directions of traffic (usually inbound and outbound). The first number represents one direction (e.g., inbound), and the second number represents the other direction (e.g., outbound). A value of 0 indicates that offloading to the NPU is not occurring for that direction of traffic. Indication of CPU-based Processing: When you see offload=0/0, it's an indication that the security profile inspection for this particular session is being processed by the CPU, rather than being offloaded to an NPU. Offloading to an NPU would typically be represented with non-zero values in this field.
upvoted 3 times
...
PoBratsky
6 months, 1 week ago
01 - session established for non-proxy traffic. 11 - client-side session established (pc->fgt), and server-side session established (fgt->server)
upvoted 1 times
...
romartinedg
7 months, 3 weeks ago
C es correcta
upvoted 1 times
...
cedigger
8 months, 4 weeks ago
Selected Answer: C
Recording to NPU Values no offloading. So C is correct
upvoted 2 times
...
stetter2006
11 months, 1 week ago
Selected Answer: C
proto_state=11
upvoted 3 times
...
fottyfan
11 months, 1 week ago
Selected Answer: C
first digit in state 11 says inspection, offload 0 means CPU is used
upvoted 3 times
...
certifi46
11 months, 2 weeks ago
Selected Answer: C
wb enabled, proto_state=11, offloa= 0/0
upvoted 2 times
...
ducduc95
1 year ago
Selected Answer: B
B, By looking at the NAT and GTW IPs, it is clear that the traffic is coming and going far. So no inspection as an ISP will do with a packet coming from a customer and going elsewhere
upvoted 1 times
...
ducduc95
1 year ago
B, By looking at the NAT and GTW IPs, it is clear that the traffic is coming and going far. So no inspection as an ISP will do with a packet coming from a customer and going elsewhere
upvoted 1 times
...
Quetchup
1 year, 1 month ago
Selected Answer: C
Enterprise_Firewall_7.0_Study_Guide-Online.pdf p 91, 92 First digit of "proto_state" value at 1 and considering all counters are at 0 for HW acceleration means CPU usage
upvoted 3 times
...
kashir
1 year, 1 month ago
C is correct, the protocol state is 11, first digit is for server which means it is processed by proxy or flow inspection
upvoted 2 times
...
djela45
1 year, 2 months ago
proto_state=11 means proxy-inspection means CPU inspects the traffic
upvoted 1 times
...
MrMaxe
1 year, 3 months ago
Selected Answer: C
I think if it was the captive portal redirection, it would need the "auth" state. as the redir state is there, it can't be "B". redir + no NPU state and offload 0/0 means the CPU did the job, so C is good. as there is a url_cat, it's not only doing IPS inspection.
upvoted 3 times
...
wisv2269
1 year, 3 months ago
It has "local" as flag. That means "Session is attached to local fortigate ip stack" which I think is because of captive portal
upvoted 1 times
...
tururu1496
1 year, 3 months ago
Selected Answer: C
pcbbj is right
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...