Q: 4
You have configured an application control profile, set peer-to-peer traffic to Block under the
Categories tab, and applied it to the firewall policy. However, your peer-to-peer traffic on known
ports is passing through the FortiGate without being blocked.
What FortiGate settings should you check to resolve this issue?
Options
Discussion
Option C
B would be my pick. Application and Filter Overrides can let specific traffic bypass the main category block if there's an override set. It's a common trap since overrides take priority, so I'd double-check those before protocol enforcement. Not 100% though, could see why C is used too.
C Saw something similar in an exam report, network protocol enforcement was the missing piece for port-based stuff.
B
C tbh, protocol enforcement trips people up a lot since App Control only catches what it identifies. If that's not blocking on standard ports, traffic sneaks through. B looks tempting but it's usually not about filters here.
Be respectful. No spam.