Question 1
Q1A pharmaceutical manufacturing facility uses a FortiGate in transparent mode to segment its Level 1 (Basic Control) and Level 2 (Supervisory Control) networks. The primary goal is to log all DNP3 traffic for auditing without disrupting real-time operations. An OT engineer has enabled promiscuous mode on the SPAN port of the industrial switch connected to the FortiGate's monitoring interface. However, FortiAnalyzer is not receiving any DNP3 traffic logs. All other system and security event logs from the FortiGate are being received correctly. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: C
In a transparent mode or offline deployment where traffic is received from a SPAN/mirror port, the corresponding FortiGate interface must be configured as a one-arm sniffer. This configuration disables the forwarding of packets and allows the FortiGate to inspect the mirrored traffic for logging and threat detection without being inline. If the interface is configured as a regular network interface, it will not process the promiscuous traffic from the SPAN port correctly for logging purposes.