nerdexam
Fortinet

FCSS_SDW_AR-7.4 · Question #15

Refer to the exhibit. The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram. When the LAN clients…

The correct answer is C. Enable auxiliary-session under config system settings. To ensure DC-1 responds via the best-performing SD-WAN member (T1) instead of defaulting to T2, enable auxiliary-session under config system settings, so reply traffic is evaluated against current route policies-not bound to the ingress interface.

SD-WAN Integration

Question

Refer to the exhibit. The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram. When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed over T2. even though T1 is the preferred member in the matching SD-WAN rule. What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?

Exhibit

FCSS_SDW_AR-7.4 question #15 exhibit

Options

  • AEnable snat-route-change under config system global.
  • BEnable reply-session under config system sdwan.
  • CEnable auxiliary-session under config system settings.
  • DFortiGate route lookup for reply traffic only considers routes over the original ingress interface.

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    77% (20)
  • D
    12% (3)

Explanation

To ensure DC-1 responds via the best-performing SD-WAN member (T1) instead of defaulting to T2, enable auxiliary-session under config system settings, so reply traffic is evaluated against current route policies-not bound to the ingress interface.

Topics

#auxiliary session#asymmetric routing#reply traffic#SD-WAN member selection

Community Discussion

No community discussion yet for this question.

Full FCSS_SDW_AR-7.4 Practice