View all questions & answers for the NSE 7 - Enterprise Firewall 7.6 Administrator Exam Materials exam
Question 21 Discussion
Comments
Selected Answers: A
FortiOS defaults to honoring the DF bit, meaning FortiGate won't fragment IP packets larger than the interface MTU.
-f option in Windows CMD ping command is for "Don't fragment"
-l option in Windows CMD ping command is for payload size of 972 bytes + 20 bytes for IP header + 8 bytes for ICMP header = 1000 bytes of FortiGate MTU
Refer to the exhibits. The configuration of Windows PC, PC 1, with a default MTU of 1500 bytes, FortiGate interfaces with an MTU of 1000 bytes, and the results of PC 1 pinging over server 172.16.0.251 are shown. Why is the PC1 user unable to ping server 172.16.0.254 and seeing the message: Packet needs to be fragmented but DF set? (Choose one answer)
Brave-Dump Clients Votes