Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE7_EFW-7.0 topic 1 question 5 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 5
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.

An administrator would like to test session failover between the two service provider connections.
What changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)

  • A. Configure set snat-route-change enable.
  • B. Change the priority of the port2 static route to 5.
  • C. Change the priority of the port1 static route to 11.
  • D. unset snat-route-change to return it to the default setting.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Comatose
Highly Voted 1 year, 3 months ago
Selected Answer: AC
It's A & C. B would just create an equal cost solution and not a failover scenario.
upvoted 11 times
...
cbu_ch
Most Recent 2 months, 2 weeks ago
Selected Answer: AC
A and C
upvoted 1 times
...
ronia
4 months, 1 week ago
Selected Answer: AC
A and C
upvoted 1 times
...
Malasxd
6 months, 1 week ago
Selected Answer: AC
A and C
upvoted 1 times
...
cedigger
8 months, 3 weeks ago
Selected Answer: AC
A and C
upvoted 1 times
...
pete79
9 months ago
vote A & C
upvoted 1 times
...
caleidoscopio
11 months ago
Correct answer: A C
upvoted 1 times
...
certifi46
11 months, 2 weeks ago
Selected Answer: AC
A and C
upvoted 1 times
...
Agent1994
11 months, 3 weeks ago
Selected Answer: AC
A, C: snat-route-changed needs to be changed to enabled (default: disabled) to make this test, and then change the priority to force traffic to go through port2. B: nope, both ports would have the same priority. D: default is disabled, and we need to enable it. Ref: Enterprise_Firewall_7.0_Study_Guide-Online 147
upvoted 4 times
...
Quetchup
1 year ago
Selected Answer: AC
Enterprise_Firewall_7.0_Study_Guide-Online.pdf p 148-149
upvoted 1 times
...
zanssanz
1 year, 1 month ago
I agree with answer A and B, the question is asking for the straight solution; I read it as either or instead of step 1 step 2, I wonder which one is the correct answer. Depending on how we read it can be A and B or A and C.
upvoted 1 times
...
Beluga123
1 year, 1 month ago
A - When 'snat-route-change' is enabled, after a routing change, routing information is flushed from existing SNAT sessions; so, the existing SNAT sessions can use the new best route C - same distance, different priority : The routing table contains the two static routes but only the one with the lowest priority is used for routing traffic.
upvoted 1 times
...
ducduc95
1 year, 2 months ago
Selected Answer: AC
vote A & C
upvoted 1 times
...
stalker1ua
1 year, 2 months ago
Selected Answer: AC
vote A & C
upvoted 1 times
...
Seph1
1 year, 2 months ago
Selected Answer: AC
A - to change the route when failover happens C - to force the failover
upvoted 2 times
...
mastheooo
1 year, 3 months ago
A & C for answer , snat-route for force existing traffic (may_dirty flag)
upvoted 1 times
...
pcbbj
1 year, 3 months ago
A and C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...