Courseiva
Advanced Networking and SD-WANmediumMultiple ChoiceObjective-mapped

How to Use SD-WAN Manual Strategy to Bypass SLA Decisions

An administrator wants to ensure that traffic from a specific source IP uses a particular SD-WAN member regardless of performance SLA results. Which SD-WAN configuration element should be used?

Quick Answer

The answer is an SD-WAN rule with a manual strategy. This configuration element allows an administrator to enforce that traffic from a specific source IP uses a particular SD-WAN member, completely overriding any performance SLA results. While SLA-based strategies dynamically select the best path based on metrics like latency or jitter, the manual strategy forces traffic to a designated member, bypassing those decisions entirely. On the Fortinet NSE 7 Advanced Security NSE7 exam, this tests your understanding of SD-WAN rule priority and how manual strategy fits within the broader SD-WAN rule manual strategy override SLA workflow. A common trap is confusing manual strategy with the "best quality" or "load balance" strategies, which still respect SLA thresholds. Remember the mnemonic: "Manual Means Mandatory" — once you set a manual strategy, the SLA is ignored for that rule.

⚠ Common exam trap

Many candidates confuse Performance SLA as a steering mechanism rather than a monitoring tool, or mistakenly think policy-based routing can achieve the same result within an SD-WAN context, but Fortinet's SD-WAN architecture requires the rule's strategy to be set to 'manual' for explicit member pinning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SD-WAN rule with manual strategy

A is correct because an SD-WAN rule with a manual strategy allows the administrator to explicitly pin traffic from a specific source IP to a particular SD-WAN member interface, overriding any performance SLA-based path selection. This is achieved by configuring the rule's 'strategy' as 'manual' and specifying the preferred member, which forces all matching traffic to use that interface regardless of SLA health.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SD-WAN rule with manual strategy

    Why this is correct

    SD-WAN rules can use manual strategy to force traffic to a specific member.

  • Route map

    Why it's wrong here

    Route maps affect routing protocol updates, not SD-WAN steering.

  • Policy-based routing on the firewall policy

    Why it's wrong here

    PBR is separate from SD-WAN; SD-WAN rules are the correct place.

  • Performance SLA

    Why it's wrong here

    Performance SLA defines thresholds, not manual routing.

About these practice questions

This NSE7 question is part of Courseiva's 940-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE7

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator wants to ensure that all traffic from a specific LAN subnet (192.168.10.0/24) to the internet uses a particular WAN interface (wan1) in an SD-WAN setup, while other traffic uses wan2. What is the correct configuration to achieve this?

medium
  • A.Create a policy-based routing rule with source 192.168.10.0/24 and set outgoing interface to wan1
  • B.Configure an SD-WAN rule with source address matching 192.168.10.0/24 and set the preferred member to wan1
  • C.Set the default route for wan1 with a higher distance
  • D.Use a route map with prefix list to match the subnet and set next-hop to wan1

Why B: In Fortinet SD-WAN, traffic steering is achieved through SD-WAN rules, not policy routes. An SD-WAN rule with a source address matching 192.168.10.0/24 and a preferred member set to wan1 ensures that all traffic from that subnet is directed to wan1, while other traffic falls through to the default SD-WAN rule or other rules using wan2. This is the correct method because SD-WAN rules are evaluated before the routing table and provide granular control over member selection based on application, source, or destination.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.