Firewall Policy Flashcards

1
Q

What are examples of objects? and used to match policies?

A

Incoming and outgoing interfaces
Source ip, user, internet service
Destination ip,, internet service
Services
Schedules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Your customer cannot select more than one source interface, how can you fix this?

A

Go to Systems > feature visibility and turn on multiple interface policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is ISDB?

A

Internet service database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How can a customer authenticate on FortiGate?

A

Local Account
Remote Server
FSSO
PKI (Certificate)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True or False: You can select both a source IP and ISDB as a source in a FW policy?

A

False, either/or

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can you use a User in the destination of a Firewall policy

A

No, only source.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Geographic based ISDB

A

Can specify and country, region, or city for and ISBN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

If you chose to match on Service, what must you enter?

A

Protocol and Port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Where do you turn on the option to have unnamed policies on the GUI?

A

System > Feature Visibility

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or False: you can create a unnamed policy on the CLI then edit it on the GUI

A

True, but you need to give the policy a unique name in order to edit it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True or false: The Video filter, VoIP and Web Application Firewall are visible on the Firewall policy page by default

A

False: it has to be turn on in the System > Feature visibility page.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which command enabled you to reduce logging and CPU usage of denied sessions?

A

config system setting
config ses-denied-traffic [disable | enable]
You can set a timer using
config system global
set block-session-timer [1-300] (30 seconds)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

If you don’t see Generate Logs when sessions starts what does that mean?

A

That your FG does not have an internal hard drive for logging.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Are IPv4 and IPv6 combined into a single combined policy?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Do policy IDs display by default on the GUI?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How can you simplify the configuration of policies?

A

Groups for addresses and/or services

15
Q

Can you delete an object if it is being used?

A

No, you have to delete references to it.

16
Q

Do disabled policies show up in policy lookup?

A

No

17
Q

h

A