nse7_sdw-70 Exam QuestionsBrowse all questions from this exam

nse7_sdw-70 Exam - Question 12


Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.

Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

Show Answer
Correct Answer: AC

The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device, which takes precedence over the SD-WAN rule. Additionally, T_INET_0_0 does not have a valid route to the destination, so the traffic gets routed over T_INET_1_0 despite the expectation for it to follow SD-WAN rule ID 1. These two reasons explain why the traffic is routed over T_INET_1_0 instead of T_INET_0_0.

Discussion

15 comments
Sign in to comment
jarzOptions: BC
Jul 20, 2023

I think it’s B and C. It’s clear that T_INET_0_0 and T_INET_0_1 have different priorities, there is no route using T_INET_0_0 interface.

jarz
Aug 26, 2023

SD-WAN interface priority, a lower value = better https://community.fortinet.com/t5/FortiGate/Technical-Tip-Assigning-Priority-to-SD-WAN-Members-for-Default/ta-p/230911

dalmiroy2k
Oct 13, 2023

Do not confuse the member configuration priority with the Priority setting available on the SD-WAN member configuration. The latter is used for the priority of static routes for members when you configure static routes for zones. The former refers to the member priority based on the Interface Preference list configuration. Members that are configured first in the list have higher priority over those configured last. The Priority setting is used as a tiebreaker for ECMP routes when matching the implicit SD-WAN rule. The priority setting in manual rule configuration displayed is 0, while minimum priority setting for SD-WAN member configuration (interface)is 1

NappelOptions: AB
Aug 31, 2023

A: Policy router have a higher precedence than a SD-WAN Rule: Page 192 SDWAN 7.2 B: The priority of T_INET_0_1 is lower than T_INET_0_0 and the mode is Manual.

mordechaydOptions: AC
May 29, 2023

A and C , priority ( on interface preferences) not considered on Manual strategy in sdwan rule

ducduc95Options: CD
Jun 23, 2023

Answers are C & D

dalmiroy2kOptions: AC
Oct 13, 2023

Do not confuse the member configuration priority with the Priority setting available on the SD-WAN member configuration. The latter is used for the priority of static routes for members when you configure static routes for zones. The former refers to the member priority based on the Interface Preference list configuration. Members that are configured first in the list have higher priority over those configured last. The Priority setting is used as a tiebreaker for ECMP routes when matching the implicit SD-WAN rule.

charrucoOptions: AC
Nov 7, 2023

A and C are correct

Michael348Options: AC
May 26, 2023

A and C. Regular policy routes have priority, so this would take priority. There's no valid route for member 1 in the rule, so C as well.

driguilimOptions: AC
May 30, 2023

A and C is correct

stickit
Jul 22, 2023

These 35 questions aren't valid anymore. Most of the questions are not from these 35. Don't waste your money

hethOptions: BC
Mar 9, 2024

Most correct answer is B and C. "Based on the output shown in the exhibit" disqualifies A as an answer.

cstevens97Options: AC
May 30, 2023

The answer is A and C

LULU23Options: AC
Jun 5, 2023

A nad C is correct

themageofsecOptions: AC
Jul 3, 2023

A, C are correct

alejof46Options: BC
Aug 14, 2023

why has priority 0, the priority is 1 to 65535. but the most correct maybe is B and C.

divided7
Oct 11, 2023

Incorrect. "Priority of the interface (0 - 65535). Used for SD-WAN rules or priority rules."

YossiV
Nov 29, 2023

From older versions, newer is from 1, and also guys, number one rule, it has to have a valid route in the routing table….

ArnauOptions: AC
Jul 17, 2024

T_INET_0_0 dosn't have a valid route