Podcast
Questions and Answers
Which type of topologies are cross-FortiGate TCP sessions often seen in?
Which type of topologies are cross-FortiGate TCP sessions often seen in?
What happens to cross-FortiGate TCP sessions if the session is unknown to the new FortiGate?
What happens to cross-FortiGate TCP sessions if the session is unknown to the new FortiGate?
What feature needs to be enabled to allow non-TCP SYN packets in cross-FortiGate TCP sessions?
What feature needs to be enabled to allow non-TCP SYN packets in cross-FortiGate TCP sessions?
What happens to a TCP session on the remote end if the new selected member connects to a different FortiGate device?
What happens to a TCP session on the remote end if the new selected member connects to a different FortiGate device?
Signup and view all the answers
What are sessions that are routed across two different FortiGate devices called?
What are sessions that are routed across two different FortiGate devices called?
Signup and view all the answers
In the topology shown on the slide, where is the PC connected?
In the topology shown on the slide, where is the PC connected?
Signup and view all the answers
What happens if the best member for steering traffic from the PC to the server changes while the TCP connection is still active?
What happens if the best member for steering traffic from the PC to the server changes while the TCP connection is still active?
Signup and view all the answers
What happens to the packets if the new best member drops them because they are not the initial TCP SYN packet or do not match any existing sessions?
What happens to the packets if the new best member drops them because they are not the initial TCP SYN packet or do not match any existing sessions?
Signup and view all the answers
How can the issue of dropped packets be solved in cross-FortiGate TCP sessions?
How can the issue of dropped packets be solved in cross-FortiGate TCP sessions?
Signup and view all the answers
What will you learn more about in another lesson?
What will you learn more about in another lesson?
Signup and view all the answers
Which setting must be enabled per V-Dom before enabling tcp-session-without-syn and disabling anti-replay?
Which setting must be enabled per V-Dom before enabling tcp-session-without-syn and disabling anti-replay?
Signup and view all the answers
What happens when a TCP session is forwarded back to the original FortiGate and the packets have invalid sequence numbers?
What happens when a TCP session is forwarded back to the original FortiGate and the packets have invalid sequence numbers?
Signup and view all the answers
What is the default expiration timer for established TCP sessions?
What is the default expiration timer for established TCP sessions?
Signup and view all the answers
What happens if port1 becomes the best member again and the TCP packets are forwarded back to Hub1?
What happens if port1 becomes the best member again and the TCP packets are forwarded back to Hub1?
Signup and view all the answers
What is the purpose of disabling the anti-replay setting?
What is the purpose of disabling the anti-replay setting?
Signup and view all the answers
How can tcp-session-without-syn and anti-replay be enabled on a firewall policy level?
How can tcp-session-without-syn and anti-replay be enabled on a firewall policy level?
Signup and view all the answers
Why should tcp-session-without-syn and anti-replay be enabled on both Hub1 and Hub2 in the dual-hub topology example?
Why should tcp-session-without-syn and anti-replay be enabled on both Hub1 and Hub2 in the dual-hub topology example?
Signup and view all the answers
What does disabling stateful firewall inspection for TCP traffic on Hub1 and Hub2 represent?
What does disabling stateful firewall inspection for TCP traffic on Hub1 and Hub2 represent?
Signup and view all the answers
What are the default values for tcp-session-without-syn and anti-replay settings?
What are the default values for tcp-session-without-syn and anti-replay settings?
Signup and view all the answers
What must be done before configuring tcp-session-without-syn and anti-replay on the firewall policy level?
What must be done before configuring tcp-session-without-syn and anti-replay on the firewall policy level?
Signup and view all the answers