Jump to content

[REQ] NSE4 7.2 Exam Dumps


Sicko

Recommended Posts

Colleagues, who knows the correct answer? I think there are 3 correct answers (B, C, D). But we need to choose two.

In which two ways can RPF checking be disabled? (Choose two.)

A. Enable anti-replay in firewall policy.

B. Enable asymmetric routing.

C. Disable strict-src-check under system settings.

D. Disable the RPF check at the FortiGate interface level for the source check.

Edited by Bob1733
Link to comment
Share on other sites

  • 2 weeks later...
On 11/14/2023 at 1:44 PM, Bob1733 said:

Colleagues, who knows the correct answer? I think there are 3 correct answers (B, C, D). But we need to choose two.

In which two ways can RPF checking be disabled? (Choose two.)

A. Enable anti-replay in firewall policy.

B. Enable asymmetric routing.

C. Disable strict-src-check under system settings.

D. Disable the RPF check at the FortiGate interface level for the source check.

about D. 

This is the hidden content, please

and between B and C take a look here :

This is the hidden content, please

C is not enough as you have to add  a supernet route as "feasible patch" or + adding the same route as the best matching one (same subnet, same prefix, same distance) but having a higher priority value than the best match one. This will force the route to be injected in the routing table as a second choice.

So B and D

  • Like 31
  • Thanks 3
Link to comment
Share on other sites

  • 2 weeks later...
  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...