Course menu

Module 7: Operations and PracticeLesson 7.4 (4 of 4 in this module)33 of 33 in the FortiGate Administrator course

Test: FortiGate Administrator

Twenty-five questions on the whole course, from policies and NAT to VPNs, profiles and HA, each with an explanation.

Intermediate · 25 min read

What you will learn

After this lesson, you can check that you can predict how a FortiGate handles traffic, choose the right configuration, and read its troubleshooting output across the whole course.

  • Policies and NAT
  • Routing and SD-WAN
  • VPNs
  • Profiles and HA

A FortiGate is a next-generation firewall running FortiOS. It routes between interfaces, allows or denies each new session with top-down firewall policies, translates addresses with source NAT and virtual IPs, terminates IPsec VPNs, inspects allowed traffic with security profiles, and can run as a high-availability cluster.

In simple terms: A firewall, router, VPN gateway and content inspector in one box, controlled by an ordered list of rules.

Twenty-five questions on the whole course, using the course lab: FGT1 with port1 (WAN, 203.0.113.2), port2 (LAN 10.0.1.0/24) and port3 (DMZ, WEB1 at 10.0.2.10). If you get one wrong, the explanation names the lesson to go back to.

Predict · scenario 1

1. In an address group with members SRV1 and SRV2, which command adds SRV3 without removing the others?

Predict · scenario 2

2. Which setting stops strangers on the Internet reaching FGT1's login page on port1?

Predict · scenario 3

3. Two interfaces are in a zone with default settings. Can hosts on one reach hosts on the other?

Predict · scenario 4

4. An accept policy for all LAN web traffic is at sequence 2; a deny for a gambling site is at sequence 5. Is the site blocked?

Predict · scenario 5

5. Debug flow shows "Denied by forward policy check (policy 0)". What does it mean?

Predict · scenario 6

6. PC1 matches the LAN-to-Internet policy, but web pages never load, and the session shows act=noop with no translated address. What is missing?

Predict · scenario 7

7. A policy has nat enable and set poolname, but users still appear as the interface address. What is missing?

Predict · scenario 8

8. In policy NAT mode, what is the destination of the policy that allows Internet users to a VIP?

Predict · scenario 9

9. The DMZ policy for a VIP has outgoing interface port1. Why does it never match?

Predict · scenario 10

10. Two default routes: port1 distance 10, port4 distance 20. Both links are up. Which is in the routing table?

Predict · scenario 11

11. Debug flow shows "reverse path check fail, drop" for a packet arriving on port2 from 172.16.9.5. What is wrong?

Predict · scenario 12

12. In which order does FortiOS look for a path for a new session?

Predict · scenario 13

13. An SD-WAN rule uses Lowest Cost (SLA) preferring port1, then port4. port1 is up but misses the SLA. Where do new matching sessions go?

Predict · scenario 14

14. A policy has source LAN-subnet and user group Staff. A user not in Staff logs in from 10.0.1.40. Does the policy match?

Predict · scenario 15

15. Users never see the captive portal when opening websites. What is most likely missing?

Predict · scenario 16

16. Which IKE phase agrees the subnets a tunnel protects?

Predict · scenario 17

17. IKE debug shows a successful SA_INIT, then AUTHENTICATION_FAILED. What do you check?

Predict · scenario 18

18. A route-based tunnel is up. HQ can reach the branch, but sessions started at the branch fail at FGT1. What is missing on FGT1?

Predict · scenario 19

19. Why add a blackhole route with distance 254 for the branch subnet?

Predict · scenario 20

20. Which phase 1 setting lets remote users connect from unknown addresses?

Predict · scenario 21

21. Antivirus is on, SSL inspection is certificate-inspection. Is malware in an HTTPS download caught?

Predict · scenario 22

22. After enabling deep inspection, every HTTPS site shows a certificate warning. Why?

Predict · scenario 23

23. Gambling is blocked by category, but a static URL filter entry exempts casino.example. Can users open it?

Predict · scenario 24

24. HA with override disabled: the higher-priority unit reboots and returns while the other has been primary. Who is primary afterwards?

Predict · scenario 25

25. A small FortiGate without a disk shows no logs from before last night's reboot. What should be configured?