SD_WAN

SD_WAN

Professional Development

70 Qs

quiz-placeholder

Similar activities

Rita4,5 PM

Rita4,5 PM

University - Professional Development

75 Qs

CHP 1 Comprehensive Medical Assisting Study Guide

CHP 1 Comprehensive Medical Assisting Study Guide

Professional Development

70 Qs

Review of BJT and FET Principles and Operations

Review of BJT and FET Principles and Operations

University - Professional Development

75 Qs

UNIT III

UNIT III

Professional Development

75 Qs

Test Your Knowledge_Hunting_AS_RO

Test Your Knowledge_Hunting_AS_RO

Professional Development

69 Qs

366-668e1a99978f8d4d5671b16e

366-668e1a99978f8d4d5671b16e

Professional Development

70 Qs

Network Fundamentals Knowledge Check - CTJP Batch 50

Network Fundamentals Knowledge Check - CTJP Batch 50

Professional Development

67 Qs

AISS - AWS SA - Acloudguru

AISS - AWS SA - Acloudguru

Professional Development

65 Qs

SD_WAN

SD_WAN

Assessment

Quiz

Other

Professional Development

Hard

Created by

Jancker jancker

FREE Resource

70 questions

Show all answers

1.

MULTIPLE SELECT QUESTION

30 sec • 1 pt

Media Image

The exhibit shows the BGP con¬guration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise pre¬xes from spokes
to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not
see the pre¬xes from other spokes and the additional paths.
Based on the exhibit, which three settings must the administrator con¬gure inside each BGP neighbor group so spokes can learn other spokes
pre¬xes and their additional paths? (Choose three.)

Enable soft-recon¬guration

Enable route-re­ector-client

Set additional-path to send

Set adv-additional-path to the number of additional paths to advertise

Set advertisement-interval to the number of additional paths to advertise

2.

MULTIPLE SELECT QUESTION

30 sec • 1 pt

What are two advantages of using an IPsec recommended template to con¬gure an IPsec tunnel in an hub-and-spoke topology? (Choose two.)

It ensures consistent settings between phase1 and phase2.

It guides the administrator to use Fortinet recommended settings.

The VPN monitor tool provides additional statistics for tunnels de¬ned with an IPsec recommended template.

It automatically install IPsec tunnels to every spoke when they are added to the FortiManager ADOM.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Media Image

Refer to the exhibit

FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.

FortiGate always blocks all tra®c, after a route change.

FortiGate performs routing lookups for new sessions only, after a route change.

FortiGate ­ushes all routing information from the session table, after a route change.

4.

MULTIPLE SELECT QUESTION

30 sec • 1 pt

In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)

It provides the bene¬ts of a full-mesh topology in a hub-and-spoke network

It enables spokes to establish shortcuts to third-party gateways

It provides direct connectivity between spokes by creating shortcuts.

It enables spokes to bypass the hub during shortcut negotiation.

5.

MULTIPLE SELECT QUESTION

30 sec • 1 pt

Media Image

The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.
The administrator wants to know through which interface FortiGate will steer the traffic from local users on subnet 10.0.1.0/255.255.255.192 and
with a destination of the business application Salesforce located on HQ servers 10.0.0.1.
Based on the exhibits, which two statements are correct? (Choose two.)

There is no service defined for the Salesforce application, so FortiGate will use the service rule 3 and steer the traffic through interface
T_HQ1

FortiGate steers traffic to HQ servers according to service rule 1 and it uses port1 or port2 because both interfaces are selected.

When FortiGate cannot recognize the application of the ­ow it steers the traffic destined to server 10.0.0.1 according to service rule 3.

FortiGate steers tra®c for business application according to service rule 2 and steers traffic through port2.

6.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Which are three key routing principles in SD-WAN? (Choose three.)

By default. SD-WAN members are skipped if they do not have a valid route to the destination

By default. SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.

FortiGate performs route lookups for new sessions only

SD-WAN rules have precedence over ISDB routes

Regular policy routes have precedence over SD-WAN rules

7.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

Media Image

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two con¬guration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)

On the hubs, net-device must be enabled on all IPsec VPNs

auto-discovery-forwarder must be enabled on all IPsec VPNs.

On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub

On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?