FortiGate Routing Modes Quiz
40 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which interface does FortiGate route packets through if the session originates from the other side?

  • port4
  • port2
  • port1 (correct)
  • port3

Which interface does the return packet arrive at if the session originated from the local workstation?

  • port4
  • port2 (correct)
  • port3
  • port1

What is the result of the return traffic following a different path than the originating traffic?

  • Security inspection is affected
  • Asymmetric routing (correct)
  • FortiGate rejects the return packet
  • Packets are dropped

Which routing mode checks that the best route to the source IP-address is through the incoming interface?

<p>Strict RPF (B)</p> Signup and view all the answers

Which routing mode accepts traffic from a specific subnet only when a specific incoming interface is used?

<p>Strict RPF (B)</p> Signup and view all the answers

Which routing mode ensures that the return packets are routed through the same interface they originated from, even if there is a better route through a different interface?

<p>Return packet routing (C)</p> Signup and view all the answers

Which device in the network topology is directly connected to FortiGate port2?

<p>Local router (D)</p> Signup and view all the answers

What is the default gateway for the local workstation?

<p>10.1.0.254 (D)</p> Signup and view all the answers

What is the purpose of FortiGate remembering the interface to source?

<p>To improve routing efficiency (C)</p> Signup and view all the answers

Why does FortiGate route the return packet through port2 instead of port1, even though port1 is the better route?

<p>To maintain traffic flow symmetry (A)</p> Signup and view all the answers

What are the three network devices in the local network 10.1.0.0/24?

<p>local workstation, local router, and FortiGate port1</p> Signup and view all the answers

Which interface is directly connected to the local router?

<p>FortiGate port2</p> Signup and view all the answers

What is the IP address of the remote server?

<p>10.4.0.1</p> Signup and view all the answers

What is the default gateway for the local workstation?

<p>10.1.0.254</p> Signup and view all the answers

Why does FortiGate remember the interface to source?

<p>To route the return packets through the same interface they originated from</p> Signup and view all the answers

What happens when an ICMP echo request is sent from the local workstation to the remote server?

<p>The packet goes to the local router first, then to FortiGate, then to the remote router, and finally to the destination</p> Signup and view all the answers

Which interface does the ICMP packet arrive at when it reaches FortiGate?

<p>port2</p> Signup and view all the answers

What is stored in the session information for the originating traffic?

<p>The next hop to the destination</p> Signup and view all the answers

Which interface does FortiGate route the return packet through?

<p>port2</p> Signup and view all the answers

What is the objective of keeping the traffic flow symmetric?

<p>To ensure that the return packets follow the same path as the originating traffic</p> Signup and view all the answers

What is the purpose of strict mode in FortiGate routing?

<p>To check that the best route to the source IP-address is through the incoming interface and that it is the best route.</p> Signup and view all the answers

What happens to traffic from 172.16.1.1 to 10.1.0.1 in strict mode?

<p>It is blocked because there is no route to the source IP-address through the incoming interface.</p> Signup and view all the answers

What happens to traffic from 10.4.0.1 to 10.1.0.1 in strict mode?

<p>It is also blocked because there is an active route to 10.4.0.1 through a different interface, but it is not the best route to the source IP-address.</p> Signup and view all the answers

What does the unit do during the second routing lookup?

<p>The unit finds the next hop (or gateway) to the source.</p> Signup and view all the answers

What is the purpose of return packet routing in FortiGate?

<p>To ensure that the return packet is routed through the same interface it originated from, even if there is a better route through a different interface.</p> Signup and view all the answers

What IP address is added to the session during the second routing lookup?

<p>The IP address of the next hop is added to the session.</p> Signup and view all the answers

Why is symmetric routing important for content inspection in FortiGate?

<p>It ensures that traffic follows the same path in both directions, allowing for effective content inspection.</p> Signup and view all the answers

What can prevent FortiGate from inspecting traffic content?

<p>Asymmetric routing, where traffic follows different paths in each direction.</p> Signup and view all the answers

What is the initial value of the session before the second routing lookup?

<p>The initial value of the session is 0.0.0.0.</p> Signup and view all the answers

What is the default routing behavior in FortiGate?

<p>Routing is kept symmetric as much as possible.</p> Signup and view all the answers

What happens if the traffic originates from the server side instead of the other side?

<p>If the traffic originates from the server side, FortiGate uses the best route to the source IP-address.</p> Signup and view all the answers

Which interface does FortiGate route packets through if the session originates from the other side?

<p>The interface that the return packets originated from.</p> Signup and view all the answers

What happens if the ICMP echo request arrives at FortiGate when there is no session yet?

<p>FortiGate uses the best route to the source IP-address.</p> Signup and view all the answers

What does FortiGate remember about the interface to source?

<p>The interface to route the return packets through.</p> Signup and view all the answers

What is the result of the return packet arriving through a different interface?

<p>The result is asymmetric routing, where the return traffic follows a different path than the originating traffic.</p> Signup and view all the answers

What is the purpose of routing traffic symmetrically in FortiGate?

<p>To ensure that the same route path is used for both directions of the traffic (symmetric routing).</p> Signup and view all the answers

What is the default gateway for the local workstation in the example shown on this slide?

<p>The default gateway for the local workstation is 10.1.0.254.</p> Signup and view all the answers

Where does the ICMP echo reply go first after arriving at the local workstation?

<p>The ICMP echo reply goes to the local router first.</p> Signup and view all the answers

Which interface does the return packet arrive at in the example shown on this slide?

<p>The return packet arrives at FortiGate port2.</p> Signup and view all the answers

What is the result of FortiGate accepting the return packet that arrives through a different interface?

<p>The result is asymmetric routing, where the return traffic follows a different path than the originating traffic.</p> Signup and view all the answers

More Like This

Use Quizgecko on...
Browser
Browser