Which two interfaces are considered overlay links? (Choose two.)
Which two interfaces are considered overlay links? (Choose two.)A . LAGB . IPsecC . PhysicalD . GREView AnswerAnswer: BD
Based on the output shown in the exhibits, which two reasons can cause the observed behavior?
Refer to the exhibits. Exhibit A shows the packet duplication rule configuration, the SD-WAN zone status output, and the sniffer output on FortiGate acting as the sender. Exhibit B shows the sniffer output on a FortiGate acting as the receiver. The administrator configured packet duplication on both FortiGate devices. The...
What are two common use cases for remote internet access (RIA)? (Choose two.)
What are two common use cases for remote internet access (RIA)? (Choose two.)A . Provide direct internet access on spokesB . Provide internet access through the hubC . Centralize security inspection on the hubD . Provide thorough inspection on spokesView AnswerAnswer: BC Explanation: B. Provide internet access through the hub:...
Which are two benefits of using CLI templates in FortiManager? (Choose two.)
Which are two benefits of using CLI templates in FortiManager? (Choose two.)A . You can reference meta fields.B . You can configure interfaces as SD-WAN members without having to remove references first.C . You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI...
Which two statements about the SD-WAN zone configuration are true? (Choose two.)
Which two statements about the SD-WAN zone configuration are true? (Choose two.)A . The service-sla-tie-break setting enables you to configure preferred member selection based on the best route to the destination.B . You can delete the default zones.C . The default zones are virtual-wan-link and SASE.D . An SD-WAN member...
Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?
Refer to the exhibit. Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?A . type must be set to static.B . mode-cfg must be enabled.C . exchange-interface-ip must be enabled.D . add-route must be disabled.View AnswerAnswer: D
Which statement best explain the cause for this issue?
Refer to the exhibits. Exhibit A shows two IPsec templates to define Branch_IPsec_1 and Branch_IPsec_2. Each template defines a VPN tunnel. Exhibit B shows the error message that FortiManager displayed when the administrator tried to assign the second template to the FortiGate device. Which statement best explain the cause for...
Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?
Refer to the exhibit. Exhibit B Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate. Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?A...
What is the route-tag setting in an SD-WAN rule used for?
What is the route-tag setting in an SD-WAN rule used for?A . To indicate the routes for health check probes.B . To indicate the destination of a rule based on learned BGP prefixes.C . To indicate the routes that can be used for routing SD-WAN traffic.D . To indicate the...
Which statement about SD-WAN zones is true?
Which statement about SD-WAN zones is true?A . An SD-WAN zone can contain only one type of interface.B . An SD-WAN zone can contain between 0 and 512 members.C . You cannot use an SD-WAN zone in static route definitions.D . You can configure up to 32 SD-WAN zones per...