New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE5_SSE_AD-7.6 Exam - Topic 3 Question 6 Discussion

Actual exam question for Fortinet's NSE5_SSE_AD-7.6 exam
Question #: 6
Topic #: 3
[All NSE5_SSE_AD-7.6 Questions]

Refer to the exhibit.

You configure SD-WAN on a standalone FortiGate device. You want to create an SD-WAN rule that steers traffic related to Facebook and LinkedIn through the less costly internet link. What must you do to set Facebook and LinkedIn applications as destinations from the GUI?

Show Suggested Answer Hide Answer
Suggested Answer: B

According to the SD-WAN 7.6 Core Administrator curriculum and the FortiOS 7.6 Administration Guide, setting common web-based services like Facebook and LinkedIn as destinations in an SD-WAN rule is primarily accomplished through the Internet Service Database (ISDB).

Internet Service vs. Application Control: In FortiOS, there is a distinction between Internet Services (which use a database of known IP addresses and ports to identify traffic at the first packet) and Applications (which require the IPS engine to inspect deeper into the packet flow to identify Layer 7 signatures).

SD-WAN Efficiency: Fortinet recommends using the Internet service field for services like Facebook and LinkedIn in SD-WAN rules because it allows the FortiGate to steer the traffic immediately upon the first packet. If the 'Application' signatures were used instead, the first session might be misrouted because the application is not identified until after the initial handshake.

GUI Configuration: As shown in the exhibit (image_b3a4c2.png), the 'Destination' section of an SD-WAN rule includes an Internet service field by default. To steer Facebook and LinkedIn traffic, the administrator simply clicks the '+' icon in that field and selects the entries for Facebook and LinkedIn from the database.

Feature Visibility (Alternative): While you can enable a specific 'Application' field in System > Feature Visibility (by enabling 'Application Detection Based SD-WAN'), this is typically used for less common applications that do not have dedicated ISDB entries. For the specific 'applications' mentioned (Facebook and LinkedIn), they are natively available in the Internet service field, making Option B the most direct and common implementation.

Why other options are incorrect:

Option A: Licensing for application signatures is part of the standard FortiGuard services and is not a prerequisite specific only to 'applications as destinations' in SD-WAN rules.

Option C: Standalone FortiGate devices fully support application-based and ISDB-based steering in SD-WAN rules.

Option D: While enabling feature visibility would add an additional field for L7 applications, it is not a 'must' for Facebook and LinkedIn, which are already accessible via the Internet Service field provided in the default GUI layout.


Contribute your Thoughts:

0/2000 characters
Chauncey
3 days ago
I'm with Lizbeth on this one. D is the way to go. Gotta make sure that applications field is visible, or you're not getting anywhere.
upvoted 0 times
...
Kate
8 days ago
Haha, option B is a classic. Like Facebook and LinkedIn are internet services. Nice try, but no cigar.
upvoted 0 times
...
Jesusa
13 days ago
Option C is just plain wrong. Of course, you can configure applications as destinations on a standalone FortiGate device.
upvoted 0 times
...
Lizbeth
18 days ago
The correct answer is D. Enabling the visibility of the applications field is the key to configuring applications as destinations for the SD-WAN rule.
upvoted 0 times
...
Diane
23 days ago
I think enabling the visibility of the applications field sounds right, but I’m not 100% confident if that’s the only step needed.
upvoted 0 times
...
Vivienne
28 days ago
I’m leaning towards option C because I vaguely remember that standalone devices have limitations with application destinations.
upvoted 0 times
...
An
1 month ago
I feel like I practiced a similar question where we had to select specific applications, but I can't recall if it was about enabling visibility first.
upvoted 0 times
...
Dortha
1 month ago
I think I remember something about needing a license for application steering, but I'm not entirely sure if that's the case for standalone devices.
upvoted 0 times
...
Maryann
1 month ago
Okay, I think I've got it. The key is that I need to enable the visibility of the applications field as destinations, as mentioned in option D. That should let me select Facebook and LinkedIn as the destinations.
upvoted 0 times
...
Dannette
2 months ago
Hmm, I'm not sure about this one. Option C says I can't configure applications as destinations on a standalone FortiGate, but the question seems to imply that I can. I'll need to double-check the details.
upvoted 0 times
...
Dana
2 months ago
I'm a bit confused here. The question says I want to steer traffic to Facebook and LinkedIn through the less costly internet link, but option B doesn't seem to match that. I'll need to think this through carefully.
upvoted 0 times
...
Willard
2 months ago
I think I'll go with option D. The question mentions that I need to enable the visibility of the applications field as destinations, so that seems like the right approach.
upvoted 0 times
...

Save Cancel