Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet NSE 7 Network Security Architect NSE7_FSN_AR-7.6 Questions and answers with CertsForce

Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions
Questions # 41:

What are two reasons you might see iprope_in check () check failed, drop when using the debug How? (Choose two.)

Options:

A.

The packet was dropped because it is not allowed by any firewall policy.


B.

The packet was dropped because there is no route to the source.


C.

The packet was dropped because the trusted host list is misconfigured


D.

The packet was dropped because the requested service is not enabled on FortiGate


Expert Solution
Questions # 42:

A FortiGate administrator is troubleshooting a VPN that is failing to establish.

As a first step, the administrator is attempting to sniff the traffic using the command:

# diagnose sniffer packet any ‘’udp port 500 or udp port 4500 or esp’’ 4

After several minutes there is still no output. What is the most Likely reason for this?

Options:

A.

The VPN is configured to use IKE over TCP


B.

esp is not a valid sniffer argument.


C.

The ISP is blocking all VPN traffic.


D.

Mismatched IKE versions are detected on the VPN peers


Expert Solution
Questions # 43:

Refer to the exhibit.

Partial output of a real-time OSPF debug is shown.

Question # 43

Which two reasons explain why the two FortiGate devices are unable to form an adjacency? (Choose two.)

Options:

A.

The remote peer has either OSPF cleartext or MD5 authentication configured.


B.

There is an OSPF authentication configuration mismatch.


C.

The local FortiGate does not have OSPF authentication configured


D.

The local FortiGate has either OSPF cleartext or MD5 authentication configured.


Expert Solution
Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions