nerdexam
Fortinet

FCSS_SDW_AR-7.4 · Question #69

The FortiGate devices are managed by ForliManager, and are configured for direct internet access (DIA). You confirm that DIA is working as expected for each branch, and check the SD- WAN zone…

The correct answer is A. The SD-WAN overlay template defines a zone for each underlay interface and moves the. The SD-WAN overlay template defines a zone for each underlay interface and moves the interfaces into those zones. This statement perfectly describes the likely sequence of events. The template, when applied, re-organizes the interfaces and zones, causing the existing firewall…

SD-WAN Deployment Strategies

Question

The FortiGate devices are managed by ForliManager, and are configured for direct internet access (DIA). You confirm that DIA is working as expected for each branch, and check the SD- WAN zone configuration and firewall policies shown in the exhibits. Then, you use the SD-WAN overlay template to configure the IPsec overlay tunnels. You create the associated SD-WAN rules to connect existing branches to the company hub device and apply the changes on the branches. After those changes, users complain that they lost internet access. DIA is no longer working. Based on the exhibit, which statement best describes the possible root cause of this issue?

Exhibits

FCSS_SDW_AR-7.4 question #69 exhibit 1
FCSS_SDW_AR-7.4 question #69 exhibit 2
FCSS_SDW_AR-7.4 question #69 exhibit 3

Options

  • AThe SD-WAN overlay template defines a zone for each underlay interface and moves the
  • BThe SD-WAN overlay template didn't configure a firewall policy to allow traffic through the overlay.
  • CThe SD-WAN overlay template redefines the interface gateway addresses if they are defined with
  • DThe SD-WAN overlay template updates the SD-WAN template and the rules.

How the community answered

(42 responses)
  • A
    83% (35)
  • B
    2% (1)
  • C
    5% (2)
  • D
    10% (4)

Explanation

The SD-WAN overlay template defines a zone for each underlay interface and moves the interfaces into those zones. This statement perfectly describes the likely sequence of events. The template, when applied, re-organizes the interfaces and zones, causing the existing firewall policy that relies on the old zone configuration to fail. This is the most plausible root cause.

Topics

#DIA#SD-WAN overlay template#IPsec overlay#FortiManager

Community Discussion

No community discussion yet for this question.

Full FCSS_SDW_AR-7.4 Practice