nerdexam
Fortinet

FCSS_SDW_AR-7.4 · Question #59

Refer to the exhibit. How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0 125?

The correct answer is A. FortiGate routes the traffic flow according to the FIB. On FortiGate, a policy route (PBR) with action deny does not drop the traffic outright. Instead, it prevents the traffic from being steered by that policy route, and the packet is then handed back to the regular routing lookup (FIB): Source 10.0.1.130 matches 10.0.1.128/25…

SD-WAN Business Application Policies

Question

Refer to the exhibit. How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0 125?

Exhibit

FCSS_SDW_AR-7.4 question #59 exhibit

Options

  • AFortiGate routes the traffic flow according to the FIB.
  • BFortiGate load balances the traffic flow through port1 and port2.
  • CFortiGate drops the traffic flow.
  • DFortiGate steers the traffic flow through port2.

How the community answered

(42 responses)
  • A
    79% (33)
  • B
    5% (2)
  • C
    2% (1)
  • D
    14% (6)

Explanation

On FortiGate, a policy route (PBR) with action deny does not drop the traffic outright. Instead, it prevents the traffic from being steered by that policy route, and the packet is then handed back to the regular routing lookup (FIB): Source 10.0.1.130 matches 10.0.1.128/25 Destination 128.66.0.125 matches 128.66.0.0/24 Router policy says action deny → do not use this policy route Result: FortiGate falls back to the FIB (normal routing table).

Topics

#FIB routing#SD-WAN rule matching#traffic steering#load balancing

Community Discussion

No community discussion yet for this question.

Full FCSS_SDW_AR-7.4 Practice