FCSS_SDW_AR-7.4 · Question #12
Refer to the exhibits. An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After…
The correct answer is B. The session 3-tuple did not match any of the existing entries in the ISDB application cache. C. FortiGate could not refresh the routing information on the session after the application was. The session 3-tuple did not match any of the existing entries in the ISDB application cache. SD-WAN app steering using Internet Service DB relies on a cache of app IP/port “3-tuples”. If the first packets of a new session don’t match an entry (e.g., GoToMeeting uses an IP not…
Question
Refer to the exhibits. An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After generating GoToMeeting test traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in the second exhibit. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1. Which two reasons explain why some log messages show that the traffic matched the implicit SD- WAN rule? (Choose two.)
Exhibits
Options
- AFull SSL inspection is not enabled on the matching firewall policy.
- BThe session 3-tuple did not match any of the existing entries in the ISDB application cache.
- CFortiGate could not refresh the routing information on the session after the application was
- DNo configured SD-WAN rule matches the traffic related to the collaboration application
How the community answered
(29 responses)- A10% (3)
- B76% (22)
- D14% (4)
Explanation
The session 3-tuple did not match any of the existing entries in the ISDB application cache. SD-WAN app steering using Internet Service DB relies on a cache of app IP/port “3-tuples”. If the first packets of a new session don’t match an entry (e.g., GoToMeeting uses an IP not yet in cache), the session is steered by the implicit rule. That’s why some logs show “implicit,” while others (when the cache later has a match) hit your explicit rule. FortiGate could not refresh the routing information on the session after the application was The path is chosen at session setup. If the app is recognized after the session is established and FortiGate can’t (or isn’t allowed to) re-route mid-session, it keeps the original SD-WAN decision (implicit rule) for that flow. Subsequent sessions may match the explicit rule once the app/IP is
Topics
Community Discussion
No community discussion yet for this question.


