View all questions & answers for the NSE 6 - Network Security 7.6 Support Engineer Materials exam
Question 25 Discussion
Comments
Selected Answers: A, D
-
Adam
2026-01-15 07:08:17
This is expectation session where FortiGate opens the pinhole port for the expected return traffic from the server to client. I believe mentioned policy_id=25 is for the original session from client to server, while that expectation session from server to client doesn't hit any firewall policy and it's allowed by FortiGate via Session Helper, such as in active FTP flow.
Selected Answers: C, D
Even though the policy ID is 25 in the example it does not mean that the traffic matches policy 25. The value 'policy_id=25' in the expect session is just a copied value from the master session, which is the oldest helper-ftp session. Once an expect session is created, it acts as a pinhole on the firewall policy. Traffic matching the expected session does not need to match or be allowed by the firewall policy to be forwarded by the system.
Selected Answers: C, D
C)
diagnose sys session list expectation -> The pinhole ports that the session helper opened can be verified using the following command to list the expectation session
D) expire=23
Refer to the exhibit. The partial output of a diagnose command is shown. Which two conclusions can you draw from the output shown in the exhibit? (Choose two answers)
Brave-Dump Clients Votes