DPolicy routes, SD-WAN rules, Internet Service Database (ISDB) routes, BGP routes
Refer to the exhibit.
You used the SD-WAN overlay orchestrator to prepare an IPsec tunnel configuration for a hub-and-spoke SD-WAN topology. The exhibit displays the FortiManager installation preview for one FortiGate device.
Based on the exhibit, which statement accurately describes the configuration applied to the FortiGate device?
AIt is a hub device. It will automatically discover the spoke devices and add them to the SD-WAN topology.
BIt is a spoke device that establishes dynamic IPsec tunnels to the hub. The local subnet range is 10.10.128.0/23.
CIt is a hub device. It can send ADVPN shortcut offers.
DIt is a spoke device that establishes dynamic IPsec tunnels to the hub. It can send auto-discovery VPN (ADVPN) shortcut requests.
Refer to the exhibits.
You collected the outputs displayed in the exhibits and need to determine which interface HTTP traffic from user device 10.0.1.101 to the corporate web server 10.0.0.126 will traverse.
All SD-WAN links are stable.
Which interface will FortiGate use to steer the traffic?
AEither HUB1-VPN1, HUB1-VPN2, or HUB1-VPN3
BOnly HUB1-VPN3
COnly HUB1-VPN2
DEither HUB1-VPN2 or HUB1-VPN3
QuestionQ6
SD-WAN troubleshooting
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
SD-WAN setup
QuestionQ8
SD-WAN setup
QuestionQ9
Rules and routing
QuestionQ10
Centralized management
QuestionQ11
Rules and routing
QuestionQ12
SD-WAN troubleshooting
QuestionQ13
SD-WAN setup
QuestionQ14
SD-WAN troubleshooting
QuestionQ15
SD-WAN troubleshooting
QuestionQ16
SD-WAN setup
QuestionQ17
Centralized management
QuestionQ18
Centralized management
QuestionQ19
SD-WAN troubleshooting
QuestionQ20
SD-WAN setup
QuestionQ21
Rules and routing
QuestionQ22
SD-WAN troubleshooting
QuestionQ23
SD-WAN setup
QuestionQ25
Rules and routing
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
-1
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
-1
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
1
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibit showing diagnose output from a FortiGate device.
Based on the output displayed in the exhibit, what can you conclude about the device role and its handling of health checks?
AThe device is a spoke and it provides embedded health-check measures for each tunnel to the hub.
BThe device is a spoke and it receives health-check measures for the tunnels of another spoke.
CThe device is a hub and it receives embedded health-check measures for each tunnel from the spoke.
DThe device is a hub and it receives health-check measures for the tunnels of a spoke.
When deploying SD-WAN, you can select from several common designs. Each design is best suited to particular contexts.
Which two statements correctly match a common SD-WAN design to its primary indication or constraint?
Choose two
AUse a standalone design for sites with only one WAN link to the cloud.
BUse a cloud on-ramp topology to improve the performance of cloud applications.
CUse a direct internet access (DIA) design to increase the traffic security and allow local devices with limited capabilities.
DUse remote breakout to centralize traffic inspection and limit local management requirements.
Refer to the exhibits.
Which two statements are correct about the health and performance of SD-WAN members 3 and 4?
Choose two
AEncrypted traffic is not used for the performance measurement
BOnly related TCP traffic is used for performance measurement.
CFortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
DThe performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
Refer to the exhibits.
You use FortiManager to configure SD-WAN across three branch devices.
When installing the device settings, FortiManager displays the error “Copy Failed” for device branch1_fgt. After clicking the log button, FortiManager shows the message in the exhibit.
Based on the exhibits, which statement best describes the issue and how it can be resolved?
ACheck the metadata variable definitions, and review the per-device mapping configuration.
BRemove the installation target for the SD-WAN member port4. You cannot combine metadata variable and installation targets.
CGateways for all members in a zone must be defined the same way. Specify the gateway of the SD-WAN member port1 without metadata variables.
DCheck the connection between branch1_fgt and FortiManager.
As an IT manager, you need to delegate installation and management of your SD-WAN deployment to a managed security service provider (MSSP).
Each site must retain direct Internet access and remain secure. You anticipate substantial traffic between the sites and want to delegate as much network administration and management as possible to the MSSP.
Which two MSSP deployment blueprints meet these requirements?
Choose two
AInstall the hub and spokes on the customer premises, and enable the MSSP to manage the SD-WAN deployment using FortiManager with a dedicated ADOM.
BUse a shared hub on the MSSP premises and a dedicated hub on the customer premises, and install the spokes on the customer premises.
CInstall a dedicated hub on the MSSP premises for the customer, and install the spokes on the customer premises.
DUse a shared hub on the MSSP premises with a dedicated VDOM for the customer, and install the spokes on the customer premises.
Refer to the exhibit.
Which SD-WAN rule and interface does FortiGate use to steer traffic from LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?
ASD-WAN service rule 3 and interface HUB1-VPN2.
BSD-WAN service rule 4 and port1 or port2.
CSD-WAN service rule 3 and interface HUB1-VPN3.
DSD-WAN service rule 4 and interface port2.
Refer to the exhibits.
The SD-WAN rule configuration, along with its corresponding rule status and routing table, is displayed.
You want to determine the expected behavior for traffic matching the SD-WAN rule at the time the output was captured.
Based on the exhibits, which behavior should you expect for traffic that matches the SD-WAN rule?
AThe traffic will be routed over HUB1-VPN1.
BThe traffic will be load balanced across all three overlays.
CThe traffic will be routed over HUB1-VPN2.
DThe traffic will be routed over HUB1-VPN3.
You use the FortiManager SD-WAN overlay orchestrator to prepare an SD-WAN deployment. Based on the information supplied through the SD-WAN overlay template wizard, FortiManager generates templates that are ready to install on the spoke and hub devices.
Which three templates does the SD-WAN overlay orchestrator create for a spoke device?
Choose three
ACLI template
BBGP template
CRules template
DStatic route template
EIPsec tunnel template
Refer to the exhibits.
You use FortiManager to manage the branch devices and configure the SD-WAN template. You update the configuration to meet new user requirements and configure the firewall policies shown in the second exhibit.
When you then use the Install Wizard to install the updated configuration and firewall policy package on the branch devices, FortiManager reports the error shown in the third exhibit.
Why is FortiManager unable to install the configuration on the branch devices?
AYou must direct traffic with the default security profile to a VPN tunnel.
BYou cannot install firewall policies that reference an SD-WAN member.
CYou cannot install firewall policies that reference an SD-WAN zone.
DYou cannot install firewall policies for HTTPS traffic with no SSL inspection.
Refer to the exhibit.
Which two conclusions are supported by the displayed output?
Choose two
AUDP traffic destined to the subnet 10.22.0.0/24 matches a policy route.
BAt least one SD-WAN rule is defined with application categories as the destination.
CAt least one SD-WAN rule allows traffic load balancing.
DUDP traffic destined to the subnet 10.22.0.0/24 matches a manual SD-WAN rule.
Refer to the exhibit.
How does FortiGate process traffic with source IP address 10.0.1.125 and destination IP address 128.66.0.125?
AFortiGate routes the traffic flow according to the forwarding information base (FIB).
BFortiGate steers the traffic flow through port7.
CFortiGate load balances the traffic flow through port7 and port8.
DFortiGate drops the traffic flow.
Refer to the exhibits.
The SD-WAN zone configuration for an SD-WAN template created on FortiManager and the policy package configuration are displayed.
When attempting to install the configuration changes, FortiManager shows an error message.
How can the issue be resolved?
AConfigure a normalized interface for the IPsec tunnel HUB1-VPN1.
BConfigure both HUB1-VPN1 and HUB1-VPN2 as the destination of policy 3.
CConfigure HUB1 as the destination of policy 3.
DConfigure branch1_fgt as the installation target for policy 3.
Which three characteristics apply to the provisioning templates available on FortiManager?
Choose three
AA CLI template can be of type CLI script or Perl script.
BA CLI template group can contain CLI templates of different types.
CCLI templates are applied in order, from top to bottom.
DEach template group can contain up to three IPsec tunnel templates.
EA template group can include a system template and an SD-WAN template.
Refer to the exhibits.
An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator gathered the information shown in the first exhibit.
After generating GoToMeeting test traffic, the administrator reviewed the related traffic log on FortiAnalyzer, shown in the second exhibit.
The administrator observed that the traffic matched the implicit SD-WAN rule, although they expected it to match rule ID 1.
Which two reasons explain why some log messages indicate that the traffic matched the implicit SD-WAN rule?
Choose two
ANo configured SD-WAN rule matches the traffic related to the collaboration application GoToMeeting.
BFull SSL inspection is not enabled on the matching firewall policy.
CThe session 3-tuple did not match any of the existing entries in the ISDB application cache.
DFortiGate could not refresh the routing information on the session after the application was detected.
Refer to the exhibit.
You plan to configure SD-WAN on a network, as illustrated in the exhibit. The network includes many FortiGate devices. Some operate as next-generation firewalls (NGFW), while others have extensions installed, such as FortiSwitch, FortiAP, or FortiExtender.
Which factors should you consider when planning the deployment?
AYou can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.
BYou should build multiple SD-WAN topologies. Each topology should contain only one type of extension.
CYou can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with FortiExtender.
DYou should exclude the FortiGate devices with FortiLink connection from the SD-WAN topology.
Refer to the exhibit.
An administrator configured two SD-WAN rules for traffic load balancing. Which interfaces does FortiGate use to steer traffic from 10.0.1.124 to 10.0.0.254?
AAny interface in the HUB1 or HUB2 zones.
BHUB1-VPN2
Cpor1 or port2
DFortiGate route the traffic according to the FIB.
Refer to the exhibit.
An event log on a FortiGate device is displayed. Based on the output displayed in the exhibit, what can you conclude about the tunnels on this device?
BThe voice traffic is steered through the VPN tunnel HUB1-VPN3.
CThere is one shortcut tunnel built from the master tunnel VPN4.
DThe VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.
Refer to the exhibits.
The administrator raises the member priority on port2 to 20. Assuming that the route exiting port2 remains valid, after the configuration changes and when new packets are received, which two actions does FortiGate take for existing sessions established through port2?
Choose two
AFortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.
BFortiGate continues routing all existing sessions over port2.
CFortiGate flags all source network address translation (SNAT) sessions as dirty only if the administrator has assigned an IP pool to the firewall policies with NAT.
DFortiGate routes new sessions over port1.
EFortiGate flags all sessions as dirty.
You are planning a large SD-WAN deployment for a global company. You want to split the network architecture into five geographic regions and deploy two hubs in each region for greater redundancy.
You anticipate substantial traffic within every region and limited traffic between spokes in separate regions. You plan to connect small branch sites only to the nearest hub in their respective regions, while connecting large branch sites to both hubs in their regions.
Which statement about this plan is true?
AIt is possible. You should use FortiManager and the overlay orchestrator multihub topology to simplify the deployment.
BIt is not possible. In a region, all spokes must have either single-hub or dual-hub connectivity.
CIt is possible. You should use EBGP as the routing protocol between the regions.
DIt is not possible. FortiOS 7.6 supports multihub topologies with up to four hubs.
Community Discussion