TechNuggets Academy

Routing and SD-WAN

Free FCP - FortiGate 7.6 Administrator practice — 6 questions on Routing and SD-WAN, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Routing and SD-WAN
A FortiGate has two static routes to 0.0.0.0/0: one via wan1 with distance 10 and priority 1, another via wan2 with distance 10 and priority 5. Both interfaces are up. How does FortiGate handle traffic matching this destination?
FortiGate selects routes first by lowest administrative distance, then among routes with equal distance, by lowest priority value. ECMP only occurs when both distance AND priority are equal. Here distances match (10) but priorities differ (1 vs 5), so only the wan1 route (priority 1) is installed as active — no load balancing happens.
Question 2 of 6 · Routing and SD-WAN
An administrator configures a policy route on a FortiGate that forwards traffic destined for 172.16.5.0/24 out wan2, but wan2's gateway becomes unreachable and the interface goes down. What happens to matching traffic?
When a policy route's outgoing interface is down or its gateway is unreachable, FortiOS considers the policy route invalid for that traffic and falls back to a normal routing table lookup, selecting the best available static/dynamic/SD-WAN route instead.
Question 3 of 6 · Routing and SD-WAN
Which ECMP load-balancing method should be selected on a FortiGate to ensure that all packets from the same client source IP consistently use the same equal-cost route, preserving session integrity for that client?
The source-ip-based ECMP method hashes on the source IP address, ensuring the same client is consistently pinned to the same route across all its ECMP-eligible connections, which is critical for maintaining session state and is FortiOS's default v4-ecmp-mode.
Question 4 of 6 · Routing and SD-WAN
A FortiGate is dual-homed to two ISPs. Return traffic for some sessions enters via wan2 even though the session's outbound SYN went out wan1, due to asymmetric routing at the upstream provider. Legitimate sessions are being dropped by the firewall. Which configuration is the most likely cause and correct fix?
Strict Uni-RPF (strict-src-check enable) forces FortiGate to only accept return traffic on the same interface the corresponding request went out on. In genuine asymmetric-routing environments this legitimately drops valid return traffic. Disabling strict-src-check (or leaving the default feasible-path/loose mode) allows the session to be accepted even when return traffic enters a different interface than expected.
Question 5 of 6 · Routing and SD-WAN
A company runs real-time VoIP traffic across three SD-WAN member links with fluctuating latency, jitter, and packet loss. Requirements state that every new call must always be placed on whichever member currently has the best real-time performance metrics, even if that changes minute to minute. Which SD-WAN rule strategy should be configured?
The Best Quality strategy continuously measures configured SLA metrics (latency, jitter, packet loss, or a combination) across all qualifying members and dynamically selects the single best-performing link for each new session at the moment it's created — exactly matching the requirement for always using the current best link.
Question 6 of 6 · Routing and SD-WAN
An SD-WAN Performance SLA (health check) is configured with a ping probe every 500ms. The link occasionally has brief, momentary latency spikes that clear within a second, but the SD-WAN rule keeps triggering failover, causing service flapping for users. Which configuration change most directly reduces unnecessary failover from brief transient spikes?
sla-fail-count and sla-pass-count define how many consecutive probe failures or successes are required before FortiOS changes the SLA target's pass/fail state. Raising these thresholds requires sustained degradation (not a single transient spike) before the link is marked as failing the SLA, directly reducing flapping from brief blips.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →