nerdexam
Fortinet

FCSS_CDS_AR-7.6 · Question #4

In an SD-WAN TGW Connect topology, which three initial steps are mandatory when routing traffic from a spoke VPC to a security VPC through a Transit Gateway? (Choose three.)

The correct answer is A. From the security VPC TGW subnet routing table, point 0.0.0.0/0 traffic to the FortiGate internal B. From the security VPC TGW subnet routing table, point 0.0.0.0/0 traffic to the TGW. E. From the spoke VPC internal routing table, point 0.0.0.0/0 traffic to the TGW. In an SD-WAN TGW Connect topology, to route spoke VPC traffic through the Security VPC FortiGate via the Transit Gateway, the following are mandatory: - The Security VPC TGW subnet route table must send 0.0.0.0/0 traffic to the TGW, so inbound spoke traffic can reach the…

FortiGate-VM Architectures in AWS

Question

In an SD-WAN TGW Connect topology, which three initial steps are mandatory when routing traffic from a spoke VPC to a security VPC through a Transit Gateway? (Choose three.)

Options

  • AFrom the security VPC TGW subnet routing table, point 0.0.0.0/0 traffic to the FortiGate internal
  • BFrom the security VPC TGW subnet routing table, point 0.0.0.0/0 traffic to the TGW.
  • CFrom both spoke VPCs and the security VPC, point 0.0.0.0/0 traffic to the Internet Gateway.
  • DFrom the security VPC FortiGate internal subnet routing table, point 0.0.0.0/0 traffic to the TGW.
  • EFrom the spoke VPC internal routing table, point 0.0.0.0/0 traffic to the TGW.

How the community answered

(44 responses)
  • A
    64% (28)
  • C
    11% (5)
  • D
    25% (11)

Explanation

In an SD-WAN TGW Connect topology, to route spoke VPC traffic through the Security VPC FortiGate via the Transit Gateway, the following are mandatory: - The Security VPC TGW subnet route table must send 0.0.0.0/0 traffic to the TGW, so inbound spoke traffic can reach the FortiGate. - The Security VPC FortiGate internal subnet route table must send 0.0.0.0/0 traffic to the FortiGate internal port, ensuring inspection. - The Spoke VPC internal route table must point 0.0.0.0/0 to the TGW, so all spoke traffic is routed via the Transit Gateway toward the Security VPC.

Topics

#Transit Gateway#SD-WAN TGW Connect#spoke VPC routing#security VPC

Community Discussion

No community discussion yet for this question.

Full FCSS_CDS_AR-7.6 Practice