ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 27 - NSE8_812 discussion

Report
Export

You are migrating the branches of a customer to FortiGate devices. They require independent routing tables on the LAN side of the network.

After reviewing the design, you notice the firewall will have many BGP sessions as you have two data centers (DC) and two ISPs per DC while each branch is using at least 10 internal segments.

Based on this scenario, what would you suggest as the more efficient solution, considering that in the future the number of internal segments, DCs or internet links per DC will increase?

A.
No change in design is needed as even small FortiGate devices have a large memory capacity.
Answers
A.
No change in design is needed as even small FortiGate devices have a large memory capacity.
B.
Acquire a FortiGate model with more capacity, considering the next 5 years growth.
Answers
B.
Acquire a FortiGate model with more capacity, considering the next 5 years growth.
C.
Implement network-id, neighbor-group and increase the advertisement-interval
Answers
C.
Implement network-id, neighbor-group and increase the advertisement-interval
D.
Redesign the SD-WAN deployment to only use a single VPN tunnel and segment traffic using VRFs on BGP
Answers
D.
Redesign the SD-WAN deployment to only use a single VPN tunnel and segment traffic using VRFs on BGP
Suggested answer: D

Explanation:

Using multiple VPN tunnels and BGP sessions for each internal segment is not scalable and efficient, especially when the number of segments, DCs or internet links per DC increases. A better solution is to use a single VPN tunnel per branch and segment traffic using virtual routing and forwarding (VRF) instances on BGP. This way, each VRF can have its own routing table and BGP session, while sharing the same VPN tunnel. Reference:

https://docs.fortinet.com/document/fortigate/6.4.0/cookbook/103439/sd-wan-with-vrf-and-bgp

asked 18/09/2024
Thomas Kincer
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first