FCSS_SDW_AR-7.4 · Question #15
Refer to the exhibit. The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram. When the LAN clients…
The correct answer is C. Enable auxiliary-session under config system settings. To ensure DC-1 responds via the best-performing SD-WAN member (T1) instead of defaulting to T2, enable auxiliary-session under config system settings, so reply traffic is evaluated against current route policies-not bound to the ingress interface.
Question
Refer to the exhibit. The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram. When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed over T2. even though T1 is the preferred member in the matching SD-WAN rule. What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?
Exhibit
Options
- AEnable snat-route-change under config system global.
- BEnable reply-session under config system sdwan.
- CEnable auxiliary-session under config system settings.
- DFortiGate route lookup for reply traffic only considers routes over the original ingress interface.
How the community answered
(26 responses)- A4% (1)
- B8% (2)
- C77% (20)
- D12% (3)
Explanation
To ensure DC-1 responds via the best-performing SD-WAN member (T1) instead of defaulting to T2, enable auxiliary-session under config system settings, so reply traffic is evaluated against current route policies-not bound to the ingress interface.
Topics
Community Discussion
No community discussion yet for this question.
