ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 2 - FCP_WCS_AD-7.4 discussion

Report
Export

Refer to the exhibit.

Which two statements are true about inbound traffic based on the IGW ingress route table and GWLB deployment shown in the exhibit? (Choose two.)

A.
GWLB forwards traffic to FortiGate without encapsulation in its dedicated subnet.
Answers
A.
GWLB forwards traffic to FortiGate without encapsulation in its dedicated subnet.
B.
Inbound traffic is directed to the GWLB through a GWLB endpoint.
Answers
B.
Inbound traffic is directed to the GWLB through a GWLB endpoint.
C.
Inbound traffic is directed to the application subnet through a GWLB endpoint.
Answers
C.
Inbound traffic is directed to the application subnet through a GWLB endpoint.
D.
GWLB encapsulates traffic with the GENEVE protocol and sends it to FortiGate.
Answers
D.
GWLB encapsulates traffic with the GENEVE protocol and sends it to FortiGate.
Suggested answer: B, D

Explanation:

Traffic Direction through GWLB Endpoint:

The ingress route table directs inbound traffic to the GWLB through a GWLB endpoint (GWLBe). This endpoint is responsible for directing traffic to the Gateway Load Balancer for further processing (Option B).

GENEVE Encapsulation:

The GWLB encapsulates the inbound traffic using the GENEVE protocol. This encapsulated traffic is then sent to FortiGate instances for security inspection. The use of GENEVE ensures that the original traffic context is preserved and can be analyzed by FortiGate (Option D).

Other Options Analysis:

Option A is incorrect because GWLB does not forward traffic without encapsulation in its dedicated subnet.

Option C is incorrect as the inbound traffic is directed to the GWLB endpoint first, not directly to the application subnet.

AWS Gateway Load Balancer Documentation: AWS GWLB

GENEVE Protocol Overview: GENEVE Protocol

asked 18/09/2024
Stephanie Scheffers
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first