Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE6_SDW_AD-7.6 Exam - Topic 4 Question 7 Discussion

You are planning a large SD-WAN deployment with approximately 1000 spokes and want to allow ADVPN between the spokes. Some remote sites use FortiSASE to connect to the company's SD-WAN hub. Which overlay routing configuration should you use?
A) BGP on loopback with dynamic BGP for ADVPN shortcut routing.
B) BGP on loopback with IPsec phase2 selectors for ADVPN shortcut routing.
C) BGP per overlay with dynamic BGP for ADVPN shortcut routing.
D) BGP per overlay with BGP next-hop convergence for ADVPN shortcut routing.

Fortinet NSE6_SDW_AD-7.6 Exam - Topic 4 Question 7 Discussion

Actual exam question for Fortinet's NSE6_SDW_AD-7.6 exam
Question #: 7
Topic #: 4
[All NSE6_SDW_AD-7.6 Questions]

You are planning a large SD-WAN deployment with approximately 1000 spokes and want to allow ADVPN between the spokes. Some remote sites use FortiSASE to connect to the company's SD-WAN hub. Which overlay routing configuration should you use?

Show Suggested Answer Hide Answer
Suggested Answer: A

For a large-scale SD-WAN deployment (such as 1000 spokes) where ADVPN shortcut routing is required and some remote sites connect via FortiSASE, the recommended overlay routing configuration is BGP running on loopback interfaces, combined with dynamic BGP for ADVPN shortcut routing. This design leverages the scalability and resilience of BGP, allowing dynamic discovery and route exchange necessary for shortcut tunnels between spokes in ADVPN environments. Using loopback interfaces for BGP peering is considered best practice because it decouples routing protocol stability from physical link status, ensuring that if a physical underlay interface fails, the BGP session remains up as long as there's an alternate path. With dynamic BGP, each spoke can efficiently learn the routes to other spokes and dynamically establish shortcuts, which is critical at this scale. This method also integrates smoothly with FortiSASE for remote connectivity to the SD-WAN hub, providing flexibility and centralized management. Reference:

[FCSS_SDW_AR-7.4 1-0.docx Q6]

Fortinet SD-WAN Reference Architecture Guide 7.4, ''Scalable Routing with BGP on Loopback and ADVPN Shortcuts''

Fortinet SD-WAN Concept Guide, ''Overlay Routing Designs for Large Deployments''


Contribute your Thoughts:

0/2000 characters
Julie
1 month ago
I disagree, B seems more secure with IPsec selectors.
upvoted 0 times
...
Truman
1 month ago
I think option A is the best choice for scalability.
upvoted 0 times
...
Nickole
2 months ago
I vaguely remember that BGP next-hop convergence might help with routing efficiency, but I’m not clear on how it applies to ADVPN specifically.
upvoted 0 times
...
Ronna
2 months ago
I feel like IPsec phase2 selectors could be relevant here, but I’m not entirely confident about how they fit into the ADVPN setup.
upvoted 0 times
...
Julianna
2 months ago
I practiced a similar question where BGP per overlay was mentioned, but I can't recall if it was for shortcut routing or something else.
upvoted 0 times
...
Deonna
2 months ago
I think I remember that BGP on loopback is often recommended for large deployments, but I'm not sure if dynamic BGP is the best choice for ADVPN shortcuts.
upvoted 0 times
...

Save Cancel