Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE5_FSW_AD-7.6 Exam - Topic 3 Question 14 Discussion

Refer to the exhibit.Port24 is the only uplink port connected to the network where you need access to FortiSwitch management services. However, FortiSwitch is not accessible on its management interface with IP address 10.0.13.3. Based on the configuration shown in the exhibit, which two actions should you take to fix the issue and access FortiSwitch? (Choose two answers)
B) Change the native VLAN on port24 to VLAN 4094. and D) Add VLAN 4094 to the allowed VLANs on port24.
A) Change the management IP address to use the VLAN 100 subnet.
C) Remove VLAN 200 from the allowed VLANs on port24.

Fortinet NSE5_FSW_AD-7.6 Exam - Topic 3 Question 14 Discussion

Actual exam question for Fortinet's NSE5_FSW_AD-7.6 exam
Question #: 14
Topic #: 3
[All NSE5_FSW_AD-7.6 Questions]

Refer to the exhibit.

Port24 is the only uplink port connected to the network where you need access to FortiSwitch management services. However, FortiSwitch is not accessible on its management interface with IP address 10.0.13.3. Based on the configuration shown in the exhibit, which two actions should you take to fix the issue and access FortiSwitch? (Choose two answers)

Show Suggested Answer Hide Answer
Suggested Answer: B, D

According to theFortiSwitchOS 7.6 Administration Guide (Page 320), management traffic on a FortiSwitch is associated with a specific logical interface, which in this case is the'internal'interface. The exhibit shows that the'internal'interface is configured onVLAN 4094(both as native and allowed). This means that for any management traffic (such as HTTPS, SSH, or SNMP) to reach the switch CPU, it must be able to traverse the physical uplink on VLAN 4094.

However, the configuration forport24(the uplink) is currently restricted. It is set withnative VLAN 100and an allowed-vlans list that only includes100 and 200. Because VLAN 4094 is not included in the allowed list of port24, all frames belonging to the management VLAN (4094) are dropped by the switch's ingress/egress filters on the uplink.

To resolve this and restore management access, the administrator has two valid configuration paths based on the provided options:

Option B:Change thenative VLAN on port24 to VLAN 4094. By making 4094 the native VLAN, untagged management traffic can traverse the port, effectively allowing the 'internal' interface to communicate with the network.

Option D:Add VLAN 4094 to the allowed VLANs on port24. This ensures that VLAN 4094 is no longer filtered out, allowing management frames to pass through the uplink while maintaining the current native VLAN for other traffic.

Option C is irrelevant as removing a working VLAN (200) does not help the management traffic. While Option A describes an alternate architectural approach (moving management into an already-allowed VLAN), Options B and D represent the direct fixes for the mismatch described in the 7.6 administration documentation.


Contribute your Thoughts:

0/2000 characters
Brianne
3 days ago
C) is definitely a no-go, we need that VLAN for other traffic!
upvoted 0 times
...
Franklyn
8 days ago
Wait, why would we change the native VLAN? That sounds risky.
upvoted 0 times
...
Elroy
13 days ago
I think B) could work too, but not sure if it's necessary.
upvoted 0 times
...
Chau
19 days ago
Totally agree, changing the IP to VLAN 100 makes sense!
upvoted 0 times
...
Renay
24 days ago
A) seems like the right move to access management.
upvoted 0 times
...
Melvin
29 days ago
I feel like adding VLAN 4094 could be a solution, but I’m not confident. D seems like a possibility based on what I studied.
upvoted 0 times
...
Glenn
1 month ago
I practiced a similar question where removing a VLAN from allowed VLANs fixed access issues. So, C might be worth considering too.
upvoted 0 times
...
Jaime
1 month ago
I'm not entirely sure, but I think changing the native VLAN might help. It seems like B could be relevant here.
upvoted 0 times
...
Rochell
1 month ago
I remember something about management IPs needing to be in the same subnet as the uplink. So, A could be a good choice.
upvoted 0 times
...

Save Cancel