Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE7_SDW-7.0 topic 1 question 4 discussion

Actual exam question from Fortinet's NSE7_SDW-7.0
Question #: 4
Topic #: 1
[All NSE7_SDW-7.0 Questions]

Refer to the exhibits.

Exhibit A -


Exhibit B -

Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

  • A. The traffic will be load balanced across all three overlays.
  • B. The traffic will be routed over T_INET_0_0.
  • C. The traffic will be routed over T_MPLS_0.
  • D. The traffic will be routed over T_INET_1_0.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Yekoy
Highly Voted 11 months, 1 week ago
Selected Answer: C
Because the gateway is enabled, Fortigate will not check if the member has a valid route to the destination, therefore MPLS will win because it has the most SLAs that are met.
upvoted 10 times
draven76
11 months ago
Sorry, I have set up a specific lab to test it. The command "set gateway enable" is not enough to "blindly" send packets to the sd-wan member. You need to also "set default enable" to make it work in that way.
upvoted 9 times
...
cabeza
6 months ago
It wont check for the "best route" with that setting, the route still needs to be there, after that it goes to SLA matching.
upvoted 1 times
...
...
draven76
Highly Voted 11 months ago
Selected Answer: D
MPLS doesn´t has valid route for destination AND set gateway enable without also set default enable will not allow packets to flow to this member without a valid route. INET_1 has route and meets one sla target (0x1). INET_0 has route but doesn´t meet sla targets (0x0)
upvoted 7 times
...
johnnd
Most Recent 2 weeks, 6 days ago
Selected Answer: C
Based on https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-deployment-for-mssps/511005/sd-wan-routing-logic
upvoted 1 times
...
alejandrofern43
2 months ago
Selected Answer: D
D. The traffic will be routed over T_INET_1_0. Most Voted Because You need to also "set default enable" to make it work in that way. pag 171 SD 72
upvoted 1 times
...
iantra123
3 months, 2 weeks ago
D: correct MPLS_0 Meet the SLA but no route to destination inet_0_0 does not meet sla (0x0), but have route inet_1_0 meet sla 0x1 and have route to destination
upvoted 2 times
...
yo86
6 months ago
Selected Answer: C
Study Guide page 94 and 145 Not A : "sla(0x0)" means member not satisfying any SLA perf as there are two sla perf configured. So T_INET_0_0 can't be used Not B : "sla(0x0)" means member not satisfying any SLA perf as there are two sla perf configured. So T_INET_0_0 can't be used Not D : "sla(0x1)" means that only SLA #1 is met. Not secondary. T_MPLS_0 met both SLA and "set gateway enable" is set, member is prior as "sla(0x3)" is mentioned despite there is no route to destination through this member
upvoted 1 times
...
charruco
6 months, 1 week ago
Selected Answer: D
T_INET_1_0 => D is correct INET_1 has route and meets one sla target (0x1).
upvoted 2 times
...
charruco
6 months, 1 week ago
T_INET_1_0 => D is correct INET_1 has route and meets one sla target (0x1).
upvoted 1 times
...
dalmiroy2k
7 months, 1 week ago
Sadly, I think the correct answer is T_MPLS_0 Even with T_INET_1_0 being succesfull in one SLA target (0x1), FortiGate checks how many SLA targets a member meets. The more SLA targets it meets, the higher its preference. If there are two or more members that meet the same number of SLA targets, then FortiGate uses the member cost as the tiebreaker, and then the member priority as the last tiebreaker. With "set gateway enable", T_MPLS_0 should skip the FIB and use gateway 172.16.1.5. It doesn't matter if that gateway may not reach 10.0.0.0/8 set default enable is missing, so SD-WAN rules are skipped if the best route to the destination isn’t an SD-WAN member. They all are.
upvoted 3 times
...
kalopilo
7 months, 1 week ago
Selected Answer: D
Please refer to page 227 SD study guide 7.2. id the sla value is 0x0 - Meaning no Sla has been met. MPLS has the most SLAs 0x3 but no route. INET_1 has 0x1 Sla Met and has a rout to destination.
upvoted 3 times
...
jarz
9 months, 2 weeks ago
Is this question missing some info? I can't see the destination for the life of me.
upvoted 1 times
...
Dogbert
9 months, 2 weeks ago
Selected Answer: D
MPLS has the most SLAs 0x3 but no route. INET_1 has one more SLA than the other. D
upvoted 2 times
...
furymistrz
10 months ago
If you want to send packets blindly through member gateway, then you must enable default and enable gateway. Please, check page 145 of SD-WAN7.0. I spent 30 minutes of analyzing that example and thinking and my conclusion is that it must be D.
upvoted 2 times
...
cstevens97
10 months, 1 week ago
Selected Answer: D
I thoroughly tested this in my home lab and strictly added the 'set gateway enable' command. Then tried to ping 8.8.4.4 from a LINUX server, with no internet routes in the FIB. The ping failed. Then I added the 'set default enable' and my ping worked. Since this configuration on the list does NOT have 'set default enable' I will continue to say the only valid answer is D. INET_1 has a valid route in this example.
upvoted 4 times
jack987
7 months, 3 weeks ago
I agree.
upvoted 1 times
...
yo86
6 months ago
it's not the question here : you opinion is based on result you're waiting for. Not about how traffic will be handled. I totally agree, it's a nonsense but correct answer is C despite that traffic will not reach destination.
upvoted 1 times
...
...
themageofsec
10 months, 2 weeks ago
Selected Answer: D
MPLS doesn´t has valid route for destination AND set gateway enable without also set default enable will not allow packets to flow to this member without a valid route. INET_1 has route and meets one sla target (0x1); INET_0 has route but doesn´t meet sla targets (0x0).
upvoted 3 times
...
themageofsec
10 months, 2 weeks ago
Selected Answer: D
MPLS doesn´t has valid route for destination AND set gateway enable without also set default enable will not allow packets to flow to this member without a valid route. INET_1 has route and meets one sla target (0x1). INET_0 has route but doesn´t meet sla targets (0x0).
upvoted 1 times
...
ducduc95
11 months ago
Selected Answer: C
To see the valid route, you should look in the database routing table. MPLS iface is a member of the sdwan rule so it has a valid route even if it is not the best(thus it is not present in the routing table)
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...