A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO). OSPF is used to redistribute routes between the offices. After deployment, a server with IP address located on the DMZ network of the BO FortiGate, was reported unreachable from hosts located on the LAN network of the same FortiGate.
Referring to the exhibit, which statement is true?

A. The ICMP packets are being blocked by an implicit deny policy.
B. A directly connected subnet is being partially superseded by an OSPF redistributed subnet.
C. Enabling NAT on the VPN firewall policy will solve the problem.
D. The incoming access list should have an accept action instead of a deny action to solve the problem.


