Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE4_FGT_AD-7.6 Exam - Topic 4 Question 8 Discussion

Refer to the exhibit.The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule NameFortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flowsWhat could be the reason?
D) FortiGate load balanced the traffic according to the implicit SD-WAN rule.
A) SD-WAN rule names do not appear immediately. The administrator must refresh the page.
B) There is no application control profile applied to the firewall policy.
C) Destinations in the SD-WAN rules are configured for each application, but feature visibility is not enabled.

Fortinet NSE4_FGT_AD-7.6 Exam - Topic 4 Question 8 Discussion

Actual exam question for Fortinet's NSE4_FGT_AD-7.6 exam
Question #: 8
Topic #: 4
[All NSE4_FGT_AD-7.6 Questions]

Refer to the exhibit.

The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule Name

FortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows

What could be the reason?

Show Suggested Answer Hide Answer
Suggested Answer: D

In FortiOS 7.6, SD-WAN steering decisions are recorded in traffic logs only when traffic matches an explicit SD-WAN rule (SD-WAN service rule). When no configured SD-WAN rule matches a session, FortiGate uses the implicit (default) SD-WAN rule/behavior to select a member (often resulting in load-balancing or default selection based on the configured SD-WAN algorithm).

In the exhibit, traffic is permitted by firewall policy ID 1, and the Destination Interface alternates between port1 and port2, but SD-WAN Rule Name remains empty. This is consistent with the sessions being forwarded by the implicit SD-WAN rule, which does not populate a named rule in the log columns.

Why the other options are not correct:

A: SD-WAN rule name logging is not a ''delayed display'' behavior requiring refresh; it is populated per-session when an explicit rule matches.

B: Application Control is not required for SD-WAN rule name to appear. Rule name logging depends on SD-WAN rule match, not on whether Application Control is enabled.

C: Feature visibility affects GUI display options, but the exhibit already shows the SD-WAN columns enabled; the issue is that no explicit SD-WAN rule is being hit.


Contribute your Thoughts:

0/2000 characters
Donte
3 hours ago
I think it's A. Just refresh the page.
upvoted 0 times
...
Frank
5 days ago
I doubt it's D, load balancing shouldn't affect rule visibility.
upvoted 0 times
...
Rasheeda
10 days ago
Wait, I didn't know SD-WAN rule names could take time to show up!
upvoted 0 times
...
Ivette
16 days ago
I disagree, it could be C, feature visibility is key!
upvoted 0 times
...
Lilli
2 months ago
Definitely B, no app control means no visibility.
upvoted 0 times
...
Ayesha
2 months ago
I think it's option A, refreshing might help.
upvoted 0 times
...
Ilda
3 months ago
D sounds plausible too, but I’m not clear on how implicit rules work in this context.
upvoted 0 times
...
Salena
3 months ago
I practiced a question similar to this, and I feel like C might be the right answer if the visibility feature isn't enabled.
upvoted 0 times
...
Helaine
3 months ago
I’m not entirely sure, but I think B could be relevant since application control profiles might affect logging.
upvoted 0 times
...
Bulah
3 months ago
I remember something about needing to refresh the page for changes to show up, so A seems possible.
upvoted 0 times
...

Save Cancel