Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE6_SDW_AD-7.6 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

(Refer to the exhibit.

Question # 21

The event log on a FortiGate device is shown.

Based on the output shown in the exhibit, what can you conclude about the tunnels on this device? (Choose one answer))

Options:

A.

There is one shortcut tunnel built from the master tunnel VPN4 .


B.

The voice traffic is steered through the VPN tunnel HUB1-VPN3 .


C.

The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.


D.

The master tunnel HUB2-VPN3 cannot accept Auto-Discovery VPN (ADVPN) shortcuts.


Expert Solution
Questions # 22:

(Which two features must you configure before FortiGate can steer traffic according to SD-WAN rules? Choose two answers.)

Options:

A.

Security profiles


B.

Underlay links


C.

Overlay links


D.

Traffic shaping


E.

Firewall policies


Expert Solution
Questions # 23:

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two.)

Options:

A.

The session information output displays no SD-WAN service id.


B.

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.


C.

The traffic is distributed, regardless of weight, through all available static routes.


D.

Traffic does not match any of the entries in the policy route table.


E.

FortiGate flags the session with may_dirty and vwl_def ault.


Expert Solution
Questions # 24:

Refer to the exhibits.

Question # 24

The exhibits show the source NAT (SNAT) global setting. port2 interface settings, and the routing table on FortiGate.

The administrator increases the member priority on port2 to 20.

Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)

Options:

A.

FortiGate continues routing all existing sessions over port2.


B.

FortiGate routes only new sessions over port2.


C.

FortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the firewall policies with NAT.


D.

FortiGate flags the sessions as dirty.


E.

FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.


Expert Solution
Questions # 25:

(Refer to the exhibit.

Question # 25

An SD-WAN zone configuration on the FortiGate GUI is shown.

What can you conclude about the zone and member configuration on this device? Choose one answer.)

Options:

A.

You can delete the virtual-wan-link zone.


B.

The WAN2 zone contains no member.


C.

You can delete the WAN1 zone.


D.

You can add the member B-125 to the WAN3 zone and keep it as a member of the Test zone.


Expert Solution
Questions # 26:

Which three factors about SLA targets and SD-WAN rules should you consider when configuring SD-WAN rules? (Choose three.)

Options:

A.

Member metrics are measured only if a rule uses the SLA target.


B.

SLA targets are used only by SD-WAN rules that are configured with a Lowest Cost (SLA) strategy.


C.

SD-WAN rules can use SLA targets to check whether the preferred members meet the SLA requirements.


D.

When configuring an SD-WAN rule, you can select multiple SLA targets if they are from the same performance SLA.


E.

When configuring an SD-WAN rule, you can select multiple SLA targets from different performance SLAs.


Expert Solution
Questions # 27:

Refer to the exhibit.

Question # 27

An administrator configures SD-WAN rules for a DIA setup using the FortiGate GUI. The page to configure the source and destination part of the rule looks as shown in the exhibit. The GUI page shows no option to configure an application as the destination of the SD-WAN rule Why?

Options:

A.

You cannot use applications as the destination when FortiGate is used for a DIA setup.


B.

FortiGate allows the configuration of applications as the destination of SD-WAN rules only on the CLI.


C.

You must enable the feature on the CLI.


D.

You must enable the feature first using the GUI menu System > Feature Visibility.


Expert Solution
Questions # 28:

Refer to the exhibit.

Question # 28

The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram.

When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed overT2. even though T1 is the preferred member in

the matching SD-WAN rule.

What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?

Options:

A.

Enable snat-route-change under config system global.


B.

Enable reply-session under config system sdwan.


C.

Enable auxiliary-session under config system settings.


D.

FortiGate route lookup for reply traffic only considers routes over the original ingress interface.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions