Firewall Policy/NAT Flashcards
What are the two ways to SNAT traffic?
- Use the outgoing interface address
- Use the dynamic IP pool
What are the four types of IP pools?
- Overload
- One-to-one
- Fixed port range
- Port block allocation
What are the two types of IP pools more commonly used for CGN?
- Fixed port range
- Port block allocation
What is the default pool type?
Overload
What are characteristics of the overload IP pool type?
- A many-to-one or many-to-few relationship
- PAT is used
How does the one-to-one pool type work?
FortiGate assigns an IP pool address to an internal host on a first-come, first-served basis
Where do you enable DNAT?
Use a VIP object on a FW policy
What is the default VIP type?
Static NAT; one-to-one
If the VIP is not referenced in an incoming firewall policy, or the policy is disabled, what happens?
It uses the external interface IP address
Do VIPs match on FW policies?
No
How does port forwarding on VIP work?
- Redirect the traffic matching the external address and port in the VIP to the mapped internal address and port
- When you enable port forwarding, FortiGate no longer performs one-to-one mapping
Which inspection mode optimizes performance?
Flow-based
What is the default inspection mode?
Flow-based
How does proxy-based inspection work?
- FortiGate buffers traffic and examines the data as a whole
- Examines more points of data than flow-based inspection
Video filter, WAF, Inline CASB, and ICAP are only available in what inspection mode?
Proxy-based