Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE7_SSE_AD-25 Exam - Topic 2 Question 2 Discussion

Actual exam question for Fortinet's NSE7_SSE_AD-25 exam
Question #: 2
Topic #: 2
[All NSE7_SSE_AD-25 Questions]

An existing Fortinet SD-WAN customer is reviewing the FortiSASE ordering guide to identify which add-on is needed to allow future FortiSASE remote users to reach private resources. Which add-on should the customer consider to allow private access? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: C

To enable remote users to access internal applications located behind an existing FortiGate SD-WAN hub, the customer must license the FortiSASE Secure Private Access (SPA) add-on.

Secure Private Access (SPA) Use Case: This specific add-on is designed to extend the Fortinet Security Fabric into the SASE cloud, allowing for a hub-and-spoke architecture where the FortiSASE PoPs act as spokes and the customer's on-premises FortiGate acts as the hub.

Licensing Requirements: The SPA add-on is a per-hub (per service connection) license. It provides the necessary entitlements to establish IPsec tunnels and BGP peering between the SASE infrastructure and the corporate FortiGate.

Feature Enablement: Once the SPA license is applied, the Configuration > Private Access menu becomes available in the FortiSASE portal. This allows administrators to define 'Service Connections' to their private data centers or cloud VPCs.

Analysis of Other Options:

Option A: The Global add-on is typically related to expanding the geographic reach or performance of the SASE PoPs, not specifically for private resource routing.

Option B: The Branch On-Ramp refers to connecting physical office locations (Thin Edge) to SASE, rather than the specific licensing for private application access for remote users.

Option D: Dedicated Public IP Address is used for source IP anchoring (SIA) to ensure remote users egress with a consistent IP for third-party SaaS IP-whitelisting.


Contribute your Thoughts:

0/2000 characters
Leslee
5 days ago
Surprised this isn't more straightforward, but I think it's the Dedicated Public IP Address add-on?
upvoted 0 times
...
Ira
10 days ago
No way, it's gotta be the Branch On-Ramp add-on!
upvoted 0 times
...
Cherelle
15 days ago
I thought it was the FortiSASE SPA add-on?
upvoted 0 times
...
Kimberlie
20 days ago
Definitely the FortiSASE Global add-on for private access.
upvoted 0 times
...
Lizbeth
26 days ago
I vaguely recall that the FortiSASE Branch On-Ramp add-on is more about connecting branches rather than remote users, so I don't think that's it.
upvoted 0 times
...
Kenneth
1 month ago
I’m a bit confused about the differences between the add-ons. I feel like the FortiSASE SPA add-on might be the one we need, but I need to double-check.
upvoted 0 times
...
Cherelle
1 month ago
I remember practicing a similar question, and I think the FortiSASE Dedicated Public IP Address add-on could be relevant for remote users.
upvoted 0 times
...
Clay
1 month ago
I think the answer might be the FortiSASE Global add-on, but I'm not entirely sure if that's the right choice for private access.
upvoted 0 times
...

Save Cancel