Fortinet NSE7_SDW-7.2 - Fortinet NSE 7 - SD-WAN 7.2 Exam

Page:    1 / 14   
Total 70 questions

Refer to the exhibit.

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.
Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)

  • A. Enable soft-reconfiguration
  • B. Enable route-reflector-client
  • C. Set additional-path to send
  • D. Set adv-additional-path to the number of additional paths to advertise
  • E. Set advertisement-interval to the number of additional paths to advertise


Answer : BCD

What are two advantages of using an IPsec recommended template to configure an IPsec tunnel in an hub-and-spoke topology? (Choose two.)

  • A. It ensures consistent settings between phase1 and phase2.
  • B. It guides the administrator to use Fortinet recommended settings.
  • C. The VPN monitor tool provides additional statistics for tunnels defined with an IPsec recommended template.
  • D. It automatically install IPsec tunnels to every spoke when they are added to the FortiManager ADOM.


Answer : AB

Refer to the exhibit.

  • A. FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.
  • B. FortiGate always blocks all traffic, after a route change.
  • C. FortiGate performs routing lookups for new sessions only, after a route change.
  • D. FortiGate flushes all routing information from the session table, after a route change.


Answer : A

In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)

  • A. It provides the benefits of a full-mesh topology in a hub-and-spoke network.
  • B. It enables spokes to establish shortcuts to third-party gateways.
  • C. It provides direct connectivity between spokes by creating shortcuts.
  • D. It enables spokes to bypass the hub during shortcut negotiation.


Answer : AC

Refer to the exhibit.

The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.
The administrator wants to know through which interface FortiGate will steer the traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the business application Salesforce located on HQ servers 10.0.0.1.
Based on the exhibits, which two statements are correct? (Choose two.)

  • A. There is no service defined for the Salesforce application, so FortiGate will use the service rule 3 and steer the traffic through interface T_HQ1.
  • B. FortiGate steers traffic to HQ servers according to service rule 1 and it uses port1 or port2 because both interfaces are selected.
  • C. When FortiGate cannot recognize the application of the flow it steers the traffic destined to server 10.0.0.1 according to service rule 3.
  • D. FortiGate steers traffic for business application according to service rule 2 and steers traffic through port2.


Answer : CD

Page:    1 / 14   
Total 70 questions