nerdexam
Fortinet

FCSS_SDW_AR-7.4 · Question #5

Refer to the exhibits. The exhibits show the source NAT (SNAT) global setting. port2 interface settings, and the routing table on FortiGate. The administrator increases the member priority on port2…

The correct answer is D. FortiGate flags the sessions as dirty. E. FortiGate updates the gateway information of the sessions with SNAT so that they use port1. With set snat-route-change enable, FortiGate updates SNAT sessions’ egress interface and gateway if a better route becomes available (e.g., port1 after priority change). The sessions are flagged as dirty, meaning their routing and SNAT details are refreshed upon new traffic…

SD-WAN Integration

Question

Refer to the exhibits. The exhibits show the source NAT (SNAT) global setting. port2 interface settings, and the routing table on FortiGate. The administrator increases the member priority on port2 to 20. Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)

Exhibits

FCSS_SDW_AR-7.4 question #5 exhibit 1
FCSS_SDW_AR-7.4 question #5 exhibit 2

Options

  • AFortiGate continues routing all existing sessions over port2.
  • BFortiGate routes only new sessions over port2.
  • CFortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the
  • DFortiGate flags the sessions as dirty.
  • EFortiGate updates the gateway information of the sessions with SNAT so that they use port1

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    10% (4)
  • D
    85% (33)

Explanation

With set snat-route-change enable, FortiGate updates SNAT sessions’ egress interface and gateway if a better route becomes available (e.g., port1 after priority change). The sessions are flagged as dirty, meaning their routing and SNAT details are refreshed upon new traffic matching the session.

Topics

#SNAT#dirty sessions#member priority#session routing

Community Discussion

No community discussion yet for this question.

Full FCSS_SDW_AR-7.4 Practice