Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE5_SSE_AD-7.6 Exam - Topic 1 Question 8 Discussion

Refer to the exhibit.You configure SD-WAN on a standalone FortiGate device. You want to create an SD-WAN rule that steers traffic related to Facebook and LinkedIn through the less costly internet link. What must you do to set Facebook and LinkedIn applications as destinations from the GUI?
B) In the Internet service field, select Facebook and LinkedIn.
A) Install a license to allow applications as destinations of SD-WAN rules.
C) You cannot configure applications as destinations of an SD-WAN rule on a standalone FortiGate device.
D) Enable the visibility of the applications field as destinations of the SD-WAN rule.

Fortinet NSE5_SSE_AD-7.6 Exam - Topic 1 Question 8 Discussion

Actual exam question for Fortinet's NSE5_SSE_AD-7.6 exam
Question #: 8
Topic #: 1
[All NSE5_SSE_AD-7.6 Questions]

Refer to the exhibit.

You configure SD-WAN on a standalone FortiGate device. You want to create an SD-WAN rule that steers traffic related to Facebook and LinkedIn through the less costly internet link. What must you do to set Facebook and LinkedIn applications as destinations from the GUI?

Show Suggested Answer Hide Answer
Suggested Answer: B

According to the SD-WAN 7.6 Core Administrator curriculum and the FortiOS 7.6 Administration Guide, setting common web-based services like Facebook and LinkedIn as destinations in an SD-WAN rule is primarily accomplished through the Internet Service Database (ISDB).

Internet Service vs. Application Control: In FortiOS, there is a distinction between Internet Services (which use a database of known IP addresses and ports to identify traffic at the first packet) and Applications (which require the IPS engine to inspect deeper into the packet flow to identify Layer 7 signatures).

SD-WAN Efficiency: Fortinet recommends using the Internet service field for services like Facebook and LinkedIn in SD-WAN rules because it allows the FortiGate to steer the traffic immediately upon the first packet. If the 'Application' signatures were used instead, the first session might be misrouted because the application is not identified until after the initial handshake.

GUI Configuration: As shown in the exhibit (image_b3a4c2.png), the 'Destination' section of an SD-WAN rule includes an Internet service field by default. To steer Facebook and LinkedIn traffic, the administrator simply clicks the '+' icon in that field and selects the entries for Facebook and LinkedIn from the database.

Feature Visibility (Alternative): While you can enable a specific 'Application' field in System > Feature Visibility (by enabling 'Application Detection Based SD-WAN'), this is typically used for less common applications that do not have dedicated ISDB entries. For the specific 'applications' mentioned (Facebook and LinkedIn), they are natively available in the Internet service field, making Option B the most direct and common implementation.

Why other options are incorrect:

Option A: Licensing for application signatures is part of the standard FortiGuard services and is not a prerequisite specific only to 'applications as destinations' in SD-WAN rules.

Option C: Standalone FortiGate devices fully support application-based and ISDB-based steering in SD-WAN rules.

Option D: While enabling feature visibility would add an additional field for L7 applications, it is not a 'must' for Facebook and LinkedIn, which are already accessible via the Internet Service field provided in the default GUI layout.


Contribute your Thoughts:

0/2000 characters
Melodie
3 hours ago
This question is tricky! I think option C is correct.
upvoted 0 times
...
Stefan
5 days ago
No way, option C can't be right!
upvoted 0 times
...
Glory
10 days ago
I think you need a license for that, so option A might be necessary.
upvoted 0 times
...
Gilberto
16 days ago
Wait, can you really not configure apps as destinations on a standalone device?
upvoted 0 times
...
Tommy
2 months ago
Totally agree, option D is the way to go!
upvoted 0 times
...
Skye
2 months ago
You need to enable the visibility of the applications field.
upvoted 0 times
...
Belen
3 months ago
I don't recall needing to select Facebook and LinkedIn directly in the Internet service field. That seems off to me.
upvoted 0 times
...
Elina
3 months ago
I’m pretty sure you need a license for applications to be used in SD-WAN rules, so option A might be correct.
upvoted 0 times
...
Lashawnda
3 months ago
I'm a bit confused about whether standalone devices can actually use applications as destinations. I feel like I saw a question like this before.
upvoted 0 times
...
Lemuel
3 months ago
I think I remember that you need to enable something in the GUI to see application options for SD-WAN rules. Maybe it's option D?
upvoted 0 times
...

Save Cancel