How to Use SD-WAN Manual Strategy to Bypass SLA Decisions
An administrator wants to ensure that traffic from a specific source IP uses a particular SD-WAN member regardless of performance SLA results. Which SD-WAN configuration element should be used?
Quick Answer
The answer is an SD-WAN rule with a manual strategy. This configuration element allows an administrator to enforce that traffic from a specific source IP uses a particular SD-WAN member, completely overriding any performance SLA results. While SLA-based strategies dynamically select the best path based on metrics like latency or jitter, the manual strategy forces traffic to a designated member, bypassing those decisions entirely. On the Fortinet NSE 7 Advanced Security NSE7 exam, this tests your understanding of SD-WAN rule priority and how manual strategy fits within the broader SD-WAN rule manual strategy override SLA workflow. A common trap is confusing manual strategy with the "best quality" or "load balance" strategies, which still respect SLA thresholds. Remember the mnemonic: "Manual Means Mandatory" — once you set a manual strategy, the SLA is ignored for that rule.
⚠ Common exam trap
Many candidates confuse Performance SLA as a steering mechanism rather than a monitoring tool, or mistakenly think policy-based routing can achieve the same result within an SD-WAN context, but Fortinet's SD-WAN architecture requires the rule's strategy to be set to 'manual' for explicit member pinning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SD-WAN rule with manual strategy
A is correct because an SD-WAN rule with a manual strategy allows the administrator to explicitly pin traffic from a specific source IP to a particular SD-WAN member interface, overriding any performance SLA-based path selection. This is achieved by configuring the rule's 'strategy' as 'manual' and specifying the preferred member, which forces all matching traffic to use that interface regardless of SLA health.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SD-WAN rule with manual strategy
Why this is correct
SD-WAN rules can use manual strategy to force traffic to a specific member.
- ✗
Route map
Why it's wrong here
Route maps affect routing protocol updates, not SD-WAN steering.
- ✗
Policy-based routing on the firewall policy
Why it's wrong here
PBR is separate from SD-WAN; SD-WAN rules are the correct place.
- ✗
Performance SLA
Why it's wrong here
Performance SLA defines thresholds, not manual routing.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE7
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator wants to ensure that all traffic from a specific LAN subnet (192.168.10.0/24) to the internet uses a particular WAN interface (wan1) in an SD-WAN setup, while other traffic uses wan2. What is the correct configuration to achieve this?
medium- A.Create a policy-based routing rule with source 192.168.10.0/24 and set outgoing interface to wan1
- ✓ B.Configure an SD-WAN rule with source address matching 192.168.10.0/24 and set the preferred member to wan1
- C.Set the default route for wan1 with a higher distance
- D.Use a route map with prefix list to match the subnet and set next-hop to wan1
Why B: In Fortinet SD-WAN, traffic steering is achieved through SD-WAN rules, not policy routes. An SD-WAN rule with a source address matching 192.168.10.0/24 and a preferred member set to wan1 ensures that all traffic from that subnet is directed to wan1, while other traffic falls through to the default SD-WAN rule or other rules using wan2. This is the correct method because SD-WAN rules are evaluated before the routing table and provide granular control over member selection based on application, source, or destination.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.