nerdexam
Fortinet

NSE7_SDW-6.4 · Question #72

Refer to the exhibit. Based on the output, which two conclusions are true? (Choose two.) FortiGate # diagnose firewall pproute list list route policy info (vf=root): id=0 dscp_tag=0xff Oxdff…

The correct answer is B. Only one SD-WAN rule has been configured. C. Entry 1 (id=1) is a regular policy route. See the full explanation below for the reasoning.

Question

Refer to the exhibit. Based on the output, which two conclusions are true? (Choose two.) FortiGate # diagnose firewall pproute list list route policy info (vf=root): id=0 dscp_tag=0xff Oxdff flags=0x00 tos=0x00 tos_mask=0x00 protocol=0 sport= 0 dport=0 dport=0-65535 oif=3 (port1) src_addr=wildcard(1): 0.0.0.0/0.0.0.0 destination_wildcard(1): 100.64.1.0/255.255.255.0 hit_count=4 last_used=2020-10-16 07:49:10 id=0x7f090003 vwl_service=1 (Google.ICMP), vwl_mbr_seq=1 2 dscp_tag=0xff Oxff flags=0x00 tos=0x00 tos_mask=0x00 protocol=0 sport=0:65535 iif=0 dport=1-65535 oif=3 (port1) oif=4 (port2) src_addr(1): 0.0.0.0-255.255.255.255 destination_wildcard(1): 0.0.0.0/0.0.0.0 Internet_service(1): IPv4svc(4294967295,0,0,0,0,0,0) hit_count=4 last_used=2020-10-16 07:49:14 id=0x7f090003 vwl_service=3 (all_rules) vwl_mbr_seq=1 dscp_tag=0xff 0xff flags=0x0 tos=0x00 tos_mask=0x00 protocol=0 sport=0:65535 iif=0 dport=1-65535 oif=3 (port1) src_addr(1): 0.0.0.0-255.255.255.255 destination(1): 0.0.0.0-255.255.255.255 hit_count=0 last_used=2020-10-16 07:49:14

Options

  • AThe all_rules rules represent the implicit SD-WAN rule.
  • BOnly one SD-WAN rule has been configured.
  • CEntry 1 (id=1) is a regular policy route.
  • DThe SD-WAN rules takes precedence over regular policy routes.

How the community answered

(30 responses)
  • A
    10% (3)
  • B
    73% (22)
  • D
    17% (5)

Community Discussion

No community discussion yet for this question.

Full NSE7_SDW-6.4 Practice