Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE8_812 Exam - Topic 4 Question 58 Discussion

SD-WAN is configured on a FortiGate. You notice that when one of the internet links has high latency the time to resolve names using DNS from FortiGate is very high.You must ensure that the FortiGate DNS resolution times are as low as possible with the least amount of work.What should you configure?
D) Configure local out traffic to use the outgoing interface based on SD-WAN rules with the interface IP and configure an SD-WAN rule to the DNS server.
A) Configure local out traffic to use the outgoing interface based on SD-WAN rules with a manual defined IP associated to a loopback interface and configure an SD-WAN rule from the loopback to the DNS server.
B) Configure an SD-WAN rule to the DNS server and use the FortiGate interface IPs in the source address.
C) Configure two DNS servers and use DNS servers recommended by the two internet providers.

Fortinet NSE8_812 Exam - Topic 4 Question 58 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 58
Topic #: 4
[All NSE8_812 Questions]

SD-WAN is configured on a FortiGate. You notice that when one of the internet links has high latency the time to resolve names using DNS from FortiGate is very high.

You must ensure that the FortiGate DNS resolution times are as low as possible with the least amount of work.

What should you configure?

Show Suggested Answer Hide Answer
Suggested Answer: D

SD-WAN is a feature that allows users to optimize network performance and reliability by using multiple WAN links and applying rules based on various criteria, such as latency, jitter, packet loss, etc. One way to ensure that the FortiGate DNS resolution times are as low as possible with the least amount of work is to configure local out traffic to use the outgoing interface based on SD-WAN rules with the interface IP and configure an SD-WAN rule to the DNS server. This means that the FortiGate will use the best WAN link available to send DNS queries to the DNS server according to the SD-WAN rule, and use its own interface IP as the source address. This avoids NAT issues and ensures optimal DNS performance. Reference: https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan/19662/sd-wan


Contribute your Thoughts:

0/2000 characters
Celia
3 hours ago
I think option B is the best. It simplifies the setup.
upvoted 0 times
...
Carmelina
5 days ago
Isn't using local DNS servers a bit outdated?
upvoted 0 times
...
Whitney
10 days ago
Definitely need to go with option D for proper routing.
upvoted 0 times
...
Rosita
16 days ago
Surprised that DNS resolution can be affected by SD-WAN rules!
upvoted 0 times
...
Barb
2 months ago
I disagree, C could work better with multiple DNS servers.
upvoted 0 times
...
Bonita
2 months ago
I think option B is the best choice for low latency.
upvoted 0 times
...
Steffanie
3 months ago
I’m leaning towards option D, but I’m not entirely confident. I just recall that using the outgoing interface based on SD-WAN rules is important for optimizing traffic.
upvoted 0 times
...
Reena
3 months ago
I practiced a question similar to this where we had to choose between using interface IPs or loopback for DNS. I feel like option B might be the right choice here.
upvoted 0 times
...
Miesha
3 months ago
I think configuring two DNS servers could help with redundancy, but I'm not clear if that would directly address the latency issue.
upvoted 0 times
...
Tiffiny
3 months ago
I remember something about using SD-WAN rules to manage traffic, but I'm not sure if the loopback interface is necessary for DNS resolution.
upvoted 0 times
...

Save Cancel