Fortinet
NSE7_SDW-6.4 · Question #72
Refer to the exhibit. Based on the output, which two conclusions are true? (Choose two.) FortiGate # diagnose firewall pproute list list route policy info (vf=root): id=0 dscp_tag=0xff Oxdff…
The correct answer is B. Only one SD-WAN rule has been configured. C. Entry 1 (id=1) is a regular policy route. See the full explanation below for the reasoning.
Question
Refer to the exhibit. Based on the output, which two conclusions are true? (Choose two.)
FortiGate # diagnose firewall pproute list
list route policy info (vf=root):
id=0 dscp_tag=0xff Oxdff flags=0x00 tos=0x00 tos_mask=0x00 protocol=0 sport=
0 dport=0 dport=0-65535 oif=3 (port1)
src_addr=wildcard(1): 0.0.0.0/0.0.0.0
destination_wildcard(1): 100.64.1.0/255.255.255.0
hit_count=4 last_used=2020-10-16 07:49:10
id=0x7f090003 vwl_service=1 (Google.ICMP), vwl_mbr_seq=1 2 dscp_tag=0xff
Oxff flags=0x00
tos=0x00 tos_mask=0x00 protocol=0 sport=0:65535 iif=0 dport=1-65535 oif=3
(port1)
oif=4 (port2)
src_addr(1): 0.0.0.0-255.255.255.255
destination_wildcard(1): 0.0.0.0/0.0.0.0
Internet_service(1): IPv4svc(4294967295,0,0,0,0,0,0)
hit_count=4 last_used=2020-10-16 07:49:14
id=0x7f090003 vwl_service=3 (all_rules) vwl_mbr_seq=1 dscp_tag=0xff 0xff
flags=0x0
tos=0x00 tos_mask=0x00 protocol=0 sport=0:65535 iif=0 dport=1-65535 oif=3
(port1)
src_addr(1): 0.0.0.0-255.255.255.255
destination(1): 0.0.0.0-255.255.255.255
hit_count=0 last_used=2020-10-16 07:49:14
Options
- AThe all_rules rules represent the implicit SD-WAN rule.
- BOnly one SD-WAN rule has been configured.
- CEntry 1 (id=1) is a regular policy route.
- DThe SD-WAN rules takes precedence over regular policy routes.
How the community answered
(30 responses)- A10% (3)
- B73% (22)
- D17% (5)
Community Discussion
No community discussion yet for this question.