NSE8_813 無料問題集「Fortinet NSE 8 - Recertification」
Refer to the exhibit, which shows a FortiGate configuration snippet.

A customer in Costa Rica has a FortiGate with SD-WAN configured to use a VPN connection to the United States to browse the internet using a public IP from that country. They would like to enable the SD-WAN rule using a webhook.
Which configuration must be added to the FortiGate, and which type of HTTP request must be used to accomplish this? (Choose two.)

A customer in Costa Rica has a FortiGate with SD-WAN configured to use a VPN connection to the United States to browse the internet using a public IP from that country. They would like to enable the SD-WAN rule using a webhook.
Which configuration must be added to the FortiGate, and which type of HTTP request must be used to accomplish this? (Choose two.)
正解:A、B
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
A customer is operating a FortiWeb cluster in a high volume active-active HA group consisting of eight FortiWeb appliances. One of the secondary members is handling traffic for one specific VIP.
What will happen with the traffic if that secondary FortiWeb appliance fails?
What will happen with the traffic if that secondary FortiWeb appliance fails?
正解:A
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
Refer to the exhibits.


During the implementation of a Fortinet Security Fabric configuration, CLI commands were issued in the order shown in the exhibit. On the next day, the local admin for FGTC issues the following command:

In this scenario, which outcome is true regarding the "subnet_1" firewall address object on FGTC?


During the implementation of a Fortinet Security Fabric configuration, CLI commands were issued in the order shown in the exhibit. On the next day, the local admin for FGTC issues the following command:

In this scenario, which outcome is true regarding the "subnet_1" firewall address object on FGTC?
正解:D
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
Refer to the exhibit. A customer has deployed a FortiGate 300E with virtual domains (VDOMs) enabled in the multi-VDOM mode. There are three VDOMs: Root is for management and internet access, while VDOM 1 and VDOM 2 are used for segregating internal traffic. AccountVInk and SalesVInk are standard VDOM links in Ethernet mode.
Given the exhibit, which two statements below about VDOM behavior are correct? (Choose two.)

Given the exhibit, which two statements below about VDOM behavior are correct? (Choose two.)

正解:A、B
解答を投票する
Refer to the exhibit, which shows a Branch1 configuration and routing table.

In the SD-WAN implicit rule, you do not want the traffic load balance for the overlay interface when all members are available.
In this scenario, which configuration change will meet this requirement?

In the SD-WAN implicit rule, you do not want the traffic load balance for the overlay interface when all members are available.
In this scenario, which configuration change will meet this requirement?
正解:A
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
Refer to the exhibit showing FortiGate configurations.

FortiManager VM high availability (HA) is not functioning as expected after being added to an existing deployment.
The administrator finds that VRRP HA mode is selected, but primary and secondary roles are greyed out in the GUI. The managed devices never show online when FMG-B becomes primary, but they will show online whenever the FMG-A becomes primary.
What change will correct HA functionality in this scenario?

FortiManager VM high availability (HA) is not functioning as expected after being added to an existing deployment.
The administrator finds that VRRP HA mode is selected, but primary and secondary roles are greyed out in the GUI. The managed devices never show online when FMG-B becomes primary, but they will show online whenever the FMG-A becomes primary.
What change will correct HA functionality in this scenario?
正解:C
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
You are investigating a problem related to FTP active mode.
You use a test PC with IP address 10.100.60.5 to connect to the FTP server at 172.16.133.50 and transfer a large file. The FortiGate translates source address (SNAT) in network
10.100.60.0/24 to the IP address 172.16.133.1.
Which two groups of CLI commands allow you to see information related to this FTP connection (Choose two.)
You use a test PC with IP address 10.100.60.5 to connect to the FTP server at 172.16.133.50 and transfer a large file. The FortiGate translates source address (SNAT) in network
10.100.60.0/24 to the IP address 172.16.133.1.
Which two groups of CLI commands allow you to see information related to this FTP connection (Choose two.)
正解:A、B
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
Refer to the exhibit containing the configuration snippets from the FortiGate.

Customer requirements:
SSLVPN Portal must be accessible on standard HTTPS port (TCP/443)
Public IP address (129.11.1.100) is assigned to port1
Datacenter.acmecorp.com resolves to the public IP address assigned to port1 The customer has a Let's Encrypt certificate that is going to expire soon and it reports that subsequent attempts to renew that certificate are failing.
Reviewing the requirement and the exhibit, which configuration change below will resolve this issue?

Customer requirements:
SSLVPN Portal must be accessible on standard HTTPS port (TCP/443)
Public IP address (129.11.1.100) is assigned to port1
Datacenter.acmecorp.com resolves to the public IP address assigned to port1 The customer has a Let's Encrypt certificate that is going to expire soon and it reports that subsequent attempts to renew that certificate are failing.
Reviewing the requirement and the exhibit, which configuration change below will resolve this issue?
正解:A
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)
Refer to the exhibits.
Topology

Configuration

The exhibits show a diagram of a requested topology and the base IPsec configuration.
A customer asks you to configure ADVPN via two internet underlays. The requirement is that you use one interface with a single IP address on DC FortiGate.
In this scenario, which feature should be implemented to achieve this requirement?
Topology

Configuration

The exhibits show a diagram of a requested topology and the base IPsec configuration.
A customer asks you to configure ADVPN via two internet underlays. The requirement is that you use one interface with a single IP address on DC FortiGate.
In this scenario, which feature should be implemented to achieve this requirement?
正解:D
解答を投票する
解説: (JPNTest メンバーにのみ表示されます)


