nerdexam
Fortinet

NSE6_SDW_AD-7.6 · Question #59

Refer to the exhibit. How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0.125?

The correct answer is A. FortiGate routes the traffic flow according to the FIB. On FortiGate, a policy route (PBR) with action deny does not drop the traffic outright. Instead, it prevents the traffic from being steered by that policy route, and the packet is then handed back to the regular routing lookup (FIB): Source 10.0.1.130 matches 10.0.1.128/25…

SD-WAN Fundamentals

Question

Refer to the exhibit. How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0.125?

Options

  • AFortiGate routes the traffic flow according to the FIB.
  • BFortiGate load balances the traffic flow through port1 and port2.
  • CFortiGate drops the traffic flow.
  • DFortiGate steers the traffic flow through port2.

How the community answered

(28 responses)
  • A
    75% (21)
  • B
    7% (2)
  • C
    14% (4)
  • D
    4% (1)

Explanation

On FortiGate, a policy route (PBR) with action deny does not drop the traffic outright. Instead, it prevents the traffic from being steered by that policy route, and the packet is then handed back to the regular routing lookup (FIB): Source 10.0.1.130 matches 10.0.1.128/25 Destination 128.66.0.125 matches 128.66.0.0/24 Router policy says action deny -> do not use this policy route Result: FortiGate falls back to the FIB (normal routing table).

Topics

#traffic routing#FIB#SD-WAN rule matching#default route behavior

Community Discussion

No community discussion yet for this question.

Full NSE6_SDW_AD-7.6 Practice