FCSS_SDW_AR-7.4 · Question #5
Refer to the exhibits. The exhibits show the source NAT (SNAT) global setting. port2 interface settings, and the routing table on FortiGate. The administrator increases the member priority on port2…
The correct answer is D. FortiGate flags the sessions as dirty. E. FortiGate updates the gateway information of the sessions with SNAT so that they use port1. With set snat-route-change enable, FortiGate updates SNAT sessions’ egress interface and gateway if a better route becomes available (e.g., port1 after priority change). The sessions are flagged as dirty, meaning their routing and SNAT details are refreshed upon new traffic…
Question
Refer to the exhibits. The exhibits show the source NAT (SNAT) global setting. port2 interface settings, and the routing table on FortiGate. The administrator increases the member priority on port2 to 20. Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)
Exhibits
Options
- AFortiGate continues routing all existing sessions over port2.
- BFortiGate routes only new sessions over port2.
- CFortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the
- DFortiGate flags the sessions as dirty.
- EFortiGate updates the gateway information of the sessions with SNAT so that they use port1
How the community answered
(39 responses)- A3% (1)
- B3% (1)
- C10% (4)
- D85% (33)
Explanation
With set snat-route-change enable, FortiGate updates SNAT sessions’ egress interface and gateway if a better route becomes available (e.g., port1 after priority change). The sessions are flagged as dirty, meaning their routing and SNAT details are refreshed upon new traffic matching the session.
Topics
Community Discussion
No community discussion yet for this question.

