NSE7 Troubleshooting and Diagnostics Practice Question
An administrator is troubleshooting an issue where a FortiGate is not forwarding traffic between two internal subnets. The administrator runs 'diagnose debug flow' and sees that packets are entering the FortiGate but are dropped with the message 'reverse path check fail, drop'. What is the MOST likely cause?
⚠ Common exam trap
Many candidates confuse reverse path check failures with policy or routing table misses, when the message specifically points to asymmetric routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Asymmetric routing: the return path for the traffic is through a different interface than the FortiGate expects.
The 'reverse path check fail' drop indicates that the FortiGate received a packet on an interface but the route back to the source would use a different interface. This is characteristic of asymmetric routing. The FortiGate performs a reverse path forwarding check to prevent spoofing and ensure symmetric routing. To resolve, the administrator can either fix the routing to be symmetric or disable the reverse path check on the interface, though that reduces security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The FortiGate's routing table does not have a route to the destination subnet.
Why it's wrong here
If there were no route to the destination, the FortiGate would drop the packet with a message indicating no route found, such as 'no route to destination'. The reverse path check failure means a route exists, but it points to a different interface than the incoming interface, causing the check to fail.
- ✓
Asymmetric routing: the return path for the traffic is through a different interface than the FortiGate expects.
Why this is correct
The reverse path check verifies that the return packet would be routed back through the same interface it arrived on. If the return route points to a different interface, the check fails and the packet is dropped. This is common in networks with multiple paths, such as when a router between subnets sends traffic through one FortiGate but the return path goes through another.
- ✗
A firewall policy is missing to allow traffic between the two subnets.
Why it's wrong here
A missing policy would result in a drop at the policy check stage, typically with a message like 'iprope_in_check() check failed, drop'. The reverse path check occurs before policy lookup, during the ingress processing. So this drop message specifically indicates a routing issue, not a missing policy.
- ✗
The two subnets are in the same zone, and intra-zone traffic is denied by default.
Why it's wrong here
Intra-zone traffic is not denied by default; it still requires a firewall policy to allow it. However, if a policy were missing, the drop would be at policy check, not reverse path check. The reverse path check is independent of zones and is based on routing. So this is not the cause of the specific drop message.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.