ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 7 - NSE8_812 discussion

Report
Export

SD-WAN is configured on a FortiGate. You notice that when one of the internet links has high latency the time to resolve names using DNS from FortiGate is very high.

You must ensure that the FortiGate DNS resolution times are as low as possible with the least amount of work.

What should you configure?

A.
Configure local out traffic to use the outgoing interface based on SD-WAN rules with a manual defined IP associated to a loopback interface and configure an SD-WAN rule from the loopback to the DNS server.
Answers
A.
Configure local out traffic to use the outgoing interface based on SD-WAN rules with a manual defined IP associated to a loopback interface and configure an SD-WAN rule from the loopback to the DNS server.
B.
Configure an SD-WAN rule to the DNS server and use the FortiGate interface IPs in the source address.
Answers
B.
Configure an SD-WAN rule to the DNS server and use the FortiGate interface IPs in the source address.
C.
Configure two DNS servers and use DNS servers recommended by the two internet providers.
Answers
C.
Configure two DNS servers and use DNS servers recommended by the two internet providers.
D.
Configure local out traffic to use the outgoing interface based on SD-WAN rules with the interface IP and configure an SD-WAN rule to the DNS server.
Answers
D.
Configure local out traffic to use the outgoing interface based on SD-WAN rules with the interface IP and configure an SD-WAN rule to the DNS server.
Suggested answer: D

Explanation:

SD-WAN is a feature that allows users to optimize network performance and reliability by using multiple WAN links and applying rules based on various criteria, such as latency, jitter, packet loss, etc. One way to ensure that the FortiGate DNS resolution times are as low as possible with the least amount of work is to configure local out traffic to use the outgoing interface based on SD-WAN rules with the interface IP and configure an SD-WAN rule to the DNS server. This means that the FortiGate will use the best WAN link available to send DNS queries to the DNS server according to the SD-WAN rule, and use its own interface IP as the source address. This avoids NAT issues and ensures optimal DNS performance. Reference: https://docs.fortinet.com/document/fortigate/7.0.0/sdwan/ 19662/sd-wan

asked 18/09/2024
Carson Plunkett
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first