Question 91

Refer to the exhibit.




The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
  • Question 92

    Refer to the exhibit.

    The exhibits show a network diagram and the explicit web proxy configuration.
    In the command diagnose sniffer packet, what filter can you use to capture the traffic between the client and the explicit web proxy?
  • Question 93

    https://www.fast2test.com/NSE4_FGT-6.4-practice-test.html 6
    Valid Fast2test NSE4_FGT-6.4 Exam PDF Dumps - New NSE4_FGT-6.4 Real Exam Questions Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
  • Question 94

    A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic, in addition, the remote peer does not support a dynamic DNS update service. What type of remote gateway should tie administrator configure on FortiGate for the new IPsec VPN tunnel to work?
  • Question 95

    Refer to the exhibit.

    The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
    Which two statements are true? (Choose two.)