Podcast
Questions and Answers
Which type of topologies are cross-FortiGate TCP sessions often seen in?
Which type of topologies are cross-FortiGate TCP sessions often seen in?
- Single-hub topologies
- Auto-discovery topologies
- Dual-hub topologies
- AD-VPN topologies (correct)
What happens to cross-FortiGate TCP sessions if the session is unknown to the new FortiGate?
What happens to cross-FortiGate TCP sessions if the session is unknown to the new FortiGate?
- The session is paused
- The session is dropped (correct)
- The session is terminated
- The session is rerouted
What feature needs to be enabled to allow non-TCP SYN packets in cross-FortiGate TCP sessions?
What feature needs to be enabled to allow non-TCP SYN packets in cross-FortiGate TCP sessions?
- tcp-session-allow-syn
- tcp-session-with-syn
- tcp-session-ignore-syn
- tcp-session-without-syn (correct)
What happens to a TCP session on the remote end if the new selected member connects to a different FortiGate device?
What happens to a TCP session on the remote end if the new selected member connects to a different FortiGate device?
What are sessions that are routed across two different FortiGate devices called?
What are sessions that are routed across two different FortiGate devices called?
In the topology shown on the slide, where is the PC connected?
In the topology shown on the slide, where is the PC connected?
What happens if the best member for steering traffic from the PC to the server changes while the TCP connection is still active?
What happens if the best member for steering traffic from the PC to the server changes while the TCP connection is still active?
What happens to the packets if the new best member drops them because they are not the initial TCP SYN packet or do not match any existing sessions?
What happens to the packets if the new best member drops them because they are not the initial TCP SYN packet or do not match any existing sessions?
How can the issue of dropped packets be solved in cross-FortiGate TCP sessions?
How can the issue of dropped packets be solved in cross-FortiGate TCP sessions?
What will you learn more about in another lesson?
What will you learn more about in another lesson?
Which setting must be enabled per V-Dom before enabling tcp-session-without-syn and disabling anti-replay?
Which setting must be enabled per V-Dom before enabling tcp-session-without-syn and disabling anti-replay?
What happens when a TCP session is forwarded back to the original FortiGate and the packets have invalid sequence numbers?
What happens when a TCP session is forwarded back to the original FortiGate and the packets have invalid sequence numbers?
What is the default expiration timer for established TCP sessions?
What is the default expiration timer for established TCP sessions?
What happens if port1 becomes the best member again and the TCP packets are forwarded back to Hub1?
What happens if port1 becomes the best member again and the TCP packets are forwarded back to Hub1?
What is the purpose of disabling the anti-replay setting?
What is the purpose of disabling the anti-replay setting?
How can tcp-session-without-syn and anti-replay be enabled on a firewall policy level?
How can tcp-session-without-syn and anti-replay be enabled on a firewall policy level?
Why should tcp-session-without-syn and anti-replay be enabled on both Hub1 and Hub2 in the dual-hub topology example?
Why should tcp-session-without-syn and anti-replay be enabled on both Hub1 and Hub2 in the dual-hub topology example?
What does disabling stateful firewall inspection for TCP traffic on Hub1 and Hub2 represent?
What does disabling stateful firewall inspection for TCP traffic on Hub1 and Hub2 represent?
What are the default values for tcp-session-without-syn and anti-replay settings?
What are the default values for tcp-session-without-syn and anti-replay settings?
What must be done before configuring tcp-session-without-syn and anti-replay on the firewall policy level?
What must be done before configuring tcp-session-without-syn and anti-replay on the firewall policy level?
Flashcards are hidden until you start studying