<< Prev Question Next Question >>

Question 101/150

A network administrator connects his PC to the INTERNAL interface on a FortiGate unit.
The administrator attempts to make an HTTPS connection to the FortiGate unit on the VLAN1 interface at the IP address of 10.0.1.1, but gets no connectivity.
The following troubleshooting commands are executed from the CLI:
user1 # get system interface
= = [ internal ]
name. internal mode. static ip: 10.0.1.254 255.255.255.128 status: up
netbios-forward. disable type. physical mtu-override. disable
= = [ vlan1 ]
name. vlan1 mode. static ip: 10.0.1.1 255.255.255.128 status: up netb
ios-forward. disable type. vlan mtu-override. disable
user1 # get router info routing-table all
Codes: K - kernel, C - connected, S - static, R - RIP, B - BGP
O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default
S 10.0.0.0/8 [10/0] is a summary, Null
C 10.0.1.0/25 is directly connected, vlan1
C 10.0.1.128/25 is directly connected, internal
user1 # diagnose debug flow trace start 100
user1 # diagnose debug ena
user1 # diagnose debug flow filter daddr 10.0.1.1 10.0.1.1
id=20085 trace_id=277 msg="vd-root received a packet(proto=6, 10.0.1.130
:47922->10.0.1.1:443) from internal."
id=20085 trace_id=277 msg="allocate a new session-00000b21"
id=20085 trace_id=277 msg="iprope_in_check() check failed, drop"
Based on the output from these commands, which of the following is a possible cause of the problem?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (150q)
Question 1: Identify the statement which correctly describes the output ...
Question 2: Data Leak Prevention archiving gives the ability to store fi...
Question 3: Which of the following methods can be used to access the CLI...
Question 4: What is 'hot swapping'?
Question 5: Which Fortinet products &amp; features could be considered p...
Question 6: When configuring FortiGuard on FortiManager, which two state...
Question 7: Which statements are true regarding securing communications ...
Question 8: What are the three different methods you can employ to send ...
Question 9: An end user logs into the SSL VPN portal and selects the Tun...
Question 10: A firewall policy has been configured such that traffic logg...
Question 11: Which of the following items does NOT support the Logging fe...
Question 12: Refer to the output below. Which statement is correct concer...
Question 13: When backing up the configuration file on a FortiGate unit, ...
Question 14: Which two statements are correct concerning the revision his...
Question 15: Which of the following statements are correct regarding the ...
Question 16: Which two statements are correct for configuration changes m...
Question 17: The following ban list entry is displayed through the CLI. g...
Question 18: In NAT/Route mode when there is no matching firewall policy ...
Question 19: Which two statements are correct regarding the FortiManager ...
Question 20: Which task categories can you select from view drop-down lis...
Question 21: Which of the following are valid FortiGate device interface ...
Question 22: An end user logs into the full-access SSL VPN portal and sel...
Question 23: Which of the following statements is correct based on the fi...
Question 24: What are the requirements for a cluster to maintain TCP conn...
Question 25: Which of the following statements best describes the green s...
Question 26: Which of the following statements is correct regarding the N...
Question 27: With FSSO, a domain user could authenticate either against t...
Question 28: The ordering of firewall policies is very important. Policie...
Question 29: In the Tunnel Mode widget of the web portal, the administrat...
Question 30: Which of the following statements are correct regarding URL ...
Question 31: What is the primary difference between raw format logs and f...
Question 32: Which of the following represents the method used on a Forti...
Question 33: Which of the following statements correctly describes the de...
Question 34: What statements are true regarding Administrative Domains (A...
Question 35: Which of the following statements is correct regarding the F...
Question 36: In the case of TCP traffic, which of the following correctly...
Question 37: Which of the following items represent the minimum configura...
Question 38: Which of the following statements are true regarding Local U...
Question 39: A FortiGate 100 unit is configured to receive push updates f...
Question 40: Which two statements are correct regarding header and footer...
Question 41: Alert emails enable the FortiGate unit to send email notific...
Question 42: What statements are true regarding disk log quota? (Choose t...
Question 43: Examine the Exhibits shown below, then answer the question t...
Question 44: Which of the following products can be installed on a comput...
Question 45: Which of the following items is NOT a packet characteristic ...
Question 46: On the Device Manager tab, what does a red circle in the Log...
Question 47: An administrator is configuring a DLP rule for FTP traffic. ...
Question 48: A firewall policy has been configured for the internal email...
Question 49: Which tabs are available on the FortiManager Web-based manag...
Question 50: Which two statements are correct regarding synchronization b...
Question 51: The FortiGate Web Config provides a link to update the firmw...
Question 52: Which of the following statements correctly describes how a ...
Question 53: Which spam filter is not available on a FortiGate device?...
Question 54: When the SSL proxy inspects the server certificate for Web F...
Question 55: A client can create a secure connection to a FortiGate devic...
Question 56: Which of the following statements regarding Banned Words are...
Question 57: Examine the exhibit shown below; then answer the question fo...
Question 58: By default the Intrusion Protection System (IPS) on a FortiG...
Question 59: Which statements are true regarding encryption settings and ...
Question 60: An administrator wants to assign a set of UTM features to a ...
Question 61: The following diagnostic output is displayed in the CLI: dia...
Question 62: Refer to the exhibit. An administrator created a new interfa...
Question 63: An administrator wishes to generate a report showing Top Tra...
Question 64: How does the Log View page display logs when ADOMs are enabl...
Question 65: Which of the following pieces of information can be included...
Question 66: Which of the following pieces of information can be included...
Question 67: Encrypted backup files provide which of the following benefi...
Question 68: A FortiGate administrator configures a Virtual Domain (VDOM)...
Question 69: Which statement is correct? FortiAnalyzer collects and aggre...
Question 70: Select the answer that describes what the CLI command diag d...
Question 71: What are the methods available to register a device? (Choose...
Question 72: Which of the following statements describes the method of cr...
Question 73: Which statements are true about Offline mode on the FortiMan...
Question 74: A FortiGate unit is configured with multiple VDOMs. An admin...
Question 75: Which of the following logging options are supported on a Fo...
Question 76: In a High Availability cluster operating in Active-Active mo...
Question 77: Users may require access to a web site that is blocked by a ...
Question 78: Which of the following Session TTL values will take preceden...
Question 79: The eicar test virus is put into a zip archive, which is giv...
Question 80: What is the purpose of locking an ADOM revision?...
Question 81: Which of the following DLP actions will override any other a...
Question 82: A network administrator needs to implement dynamic route red...
Question 83: When creating administrative users which of the following co...
Question 84: If no firewall policy is specified between two FortiGate int...
Question 85: What effect do administrative domains (ADOM) have on report ...
Question 86: A FortiGate 60 unit is configured for your small office. The...
Question 87: What is the FortiGate unit password recovery process?...
Question 88: Which of the following statements correctly describe Transpa...
Question 89: Refer to the exhibit. Examine the logs from the FortiView &g...
Question 90: Two FortiGate devices fail to form an HA cluster, the device...
Question 91: An issue could potentially occur when clicking Connect to st...
Question 92: Which statement is true regarding the import/export feature?...
Question 93: The FortiGate Server Authentication Extensions (FSAE) provid...
Question 94: Which statement is correct regarding provisioning templates?...
Question 95: For Data Leak Prevention, which of the following describes t...
Question 96: Which of the following methods does the FortiGate unit use t...
Question 97: How can DLP file filters be configured to detect Office 2010...
Question 98: Which of the following network protocols can be used to acce...
Question 99: In which of the following report templates would you configu...
Question 100: A DLP rule with an action of Exempt has been matched against...
Question 101: A network administrator connects his PC to the INTERNAL inte...
Question 102: A user selects Install Config for a managed FortiGate device...
Question 103: An administrator logs into a FortiGate unit using an account...
Question 104: What is the problem with the following SQL SELECT statement?...
Question 105: What are the limitations when creating a chart using the Cus...
Question 106: Which of the following statements are true of the FortiGate ...
Question 107: Review the static route configuration for IPsec shown in the...
Question 108: What advantages are there in using a hub-and-spoke IPSec VPN...
Question 109: Which of the following tasks fall under the responsibility o...
Question 110: Which of the following cannot be used in conjunction with th...
Question 111: Review the IKE debug output for IPsec shown in the Exhibit b...
Question 112: An organization wishes to protect its SIP Server from call f...
Question 113: Which of the following methods is best suited to changing de...
Question 114: Examine the static route configuration shown below; then ans...
Question 115: Examine the Exhibit shown below; then answer the question fo...
Question 116: Which of the following email spam filtering features is NOT ...
Question 117: You are the administrator in charge of a FortiGate unit whic...
Question 118: What statements are true regarding RAID? (Choose three.)...
Question 119: When firewall policy authentication is enabled, only traffic...
Question 120: Which of the following DLP actions will always be performed ...
Question 121: Which statements are true of Administrative Domains (ADOMs) ...
Question 122: Which of the following options can you use to update the vir...
Question 123: Which two statements are correct regarding the "Import all O...
Question 124: If Open Shortest Path First (OSPF) has already been configur...
Question 125: The Host Check feature can be enabled on the FortiGate unit ...
Question 126: Which of the following components are contained in all Forti...
Question 127: A user creates a policy package with two installation target...
Question 128: Workflow mode includes which new permissions for Super_Admin...
Question 129: Two-factor authentication is supported using the following m...
Question 130: You wish to create a firewall policy that applies only to tr...
Question 131: A static route is configured for a FortiGate unit from the C...
Question 132: Which of the following methods can be used to access the CLI...
Question 133: Which of the following statements is correct regarding a For...
Question 134: Both the FortiGate and FortiAnalyzer units can notify admini...
Question 135: A FortiGate unit is configured to receive push updates from ...
Question 136: Which of the following statements regarding Banned Words are...
Question 137: If Routing Information Protocol (RIP) version 1 or version 2...
Question 138: Because changing the operational mode to Transparent resets ...
Question 139: Review the IPsec diagnostics output of the command diag vpn ...
Question 140: Review the output of the command get router info routing-tab...
Question 141: What are the main management wizards used in Device Manager?...
Question 142: Review the IPsec Phase2 configuration shown in the Exhibit; ...
Question 143: CORRECT TEXT The __________ CLI command is used on the Forti...
Question 144: A portion of the device listing for a FortiAnalyzer unit is ...
Question 145: Under the System Information widget on the dashboard, which ...
Question 146: The command structure of the FortiGate CLI consists of comma...
Question 147: Which two statements are correct regarding recovery logic us...
Question 148: Which two statements describe a "modified" device settings' ...
Question 149: Which of the following statements is correct regarding the a...
Question 150: Which of the following are valid authentication user group t...