NSE7 Troubleshooting and Diagnostics Practice Question
A FortiGate administrator is troubleshooting an issue where users are unable to access a web server behind the FortiGate. The web server is on the DMZ network, and users are on the internal network. The firewall policy from internal to DMZ is configured to allow HTTP and HTTPS. The administrator runs 'diagnose debug flow' and sees that packets are being dropped with the message 'iprope_in_check() check failed, drop'. Which two actions should the administrator take to resolve this issue? (Choose two.)
⚠ Common exam trap
The trap here is assuming that routing or server issues cause the policy check failure, when in fact the drop is specifically due to policy lookup, so policy configuration and order must be examined.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the firewall policy from internal to DMZ is correctly configured with the correct source and destination interfaces and addresses.
The 'iprope_in_check()' drop indicates that the packet failed the inbound policy check. This can happen if the policy is misconfigured, such as incorrect interfaces or addresses, or if a preceding policy is denying the traffic. Therefore, verifying the policy configuration and its order are the correct actions. Routing and server-side issues would produce different symptoms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify that the firewall policy from internal to DMZ is correctly configured with the correct source and destination interfaces and addresses.
Why this is correct
The drop occurs during inbound policy check, which means the packet does not match any policy. Checking the policy configuration ensures that the source interface (internal), destination interface (DMZ), and addresses are correct. A misconfiguration here would cause the drop.
- ✗
Check the FortiGate's ARP table for the web server's MAC address.
Why it's wrong here
ARP issues would affect communication after the policy check. The drop is at policy enforcement, so ARP is not relevant at this stage. The FortiGate would only need ARP for the destination if the policy allowed the traffic and it was being forwarded.
- ✗
Verify that the web server is listening on the correct ports and is reachable from the FortiGate.
Why it's wrong here
If the web server is not listening or unreachable, the FortiGate might still allow the packet but the connection would fail later. The drop in debug flow is at the policy check stage, before the packet is sent to the server, so server availability is not the immediate cause.
- ✓
Ensure that the policy is placed in the correct order in the firewall policy list, as a previous policy might be blocking the traffic.
Why this is correct
Firewall policies are processed in order. If a previous policy matches the traffic and denies it, the packet will be dropped. The 'iprope_in_check' drop could occur if a deny policy is hit before the allow policy. Checking policy order is crucial.
- ✗
Check the routing table to ensure there is a route to the DMZ network.
Why it's wrong here
The 'iprope_in_check' drop is related to policy, not routing. While routing is important, a missing route would typically result in a different drop message, such as 'no route to destination'. The error indicates a policy lookup failure, so routing is less likely the cause.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.