NSE7 · domain
Advanced Networking and SD-WAN
This domain covers FortiGate routing and SD-WAN: policy routes, multiple VRF tables, link-failure detection for OSPF/BGP convergence, and redistribution between static routes and OSPF areas. Questions are scenario-based, asking you to pick the correct feature or predict how a route appears in the routing table after configuration.
Focused practice
Practice Advanced Networking and SD-WAN questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Advanced Networking and SD-WAN
Be able to select the right FortiGate feature for a routing scenario and predict the resulting routing-table entry. The single most important thing: know when policy routes, VRFs, BFD, or OSPF redistribution apply, and how each changes route selection and convergence.
Policy routes that override the routing table based on source IP or other criteria
Configuring multiple VRF instances within a single VDOM for isolated routing tables
OSPF multi-area redistribution of static routes and resulting routing-table entries
Watch out for
Common Advanced Networking and SD-WAN exam traps
- ▸Assuming policy routes permanently replace the routing table instead of being evaluated before it for matching traffic
- ▸Confusing BFD with link-monitor or SD-WAN health checks, which operate at different layers and timescales
- ▸Expecting a redistributed static route to appear as OSPF external without checking route type, metric, and area context
Question index
All Advanced Networking and SD-WAN questions (125)
Click any question to see the full explanation, or start a practice session above.
What is the purpose of BFD (Bidirectional Forwarding Detection) in a FortiGate routing configuration?
Easy2An administrator wants to use a FortiGate to manage FortiSwitch units via the LAN. Which interface configuration is required on the FortiGate to allow this management?
Easy3An administrator wants to use FortiExtender to provide LTE WAN connectivity. After connecting the FortiExtender to the FortiGate, the LTE interface is not showing up. What is the first troubleshooting step?
Medium4An administrator is troubleshooting an SD-WAN setup where a specific application's traffic is not being steered according to the configured SD-WAN rule. The rule uses a performance SLA and the 'lowest-cost' strategy. The administrator runs 'diagnose sys sdwan health-check' and sees that both members are alive and meeting the SLA. However, traffic still goes over the higher-cost member. What is the most likely cause?
Hard5A network admin configures OSPF on a FortiGate with multiple areas, including one area that is not directly connected to the backbone (Area 0). To ensure that routes from that area are advertised into other areas, which OSPF feature must be properly configured?
Medium6Which SD-WAN load balancing algorithm is best for ensuring that all traffic from a specific source-destination pair uses the same WAN link?
Easy7A FortiGate is configured with multiple virtual routers (VRFs). The administrator wants to allow communication between two VRFs using a firewall policy. Which type of interface is required for the policy?
Easy8A multi-area OSPF network includes a FortiGate as an ABR. The administrator needs to redistribute a static route into OSPF. Which command is required on the FortiGate to achieve this?
Medium9An administrator wants to integrate a FortiExtender with a FortiGate to provide cellular WAN connectivity. Which configuration step is required on the FortiGate to use the FortiExtender as an SD-WAN member?
Medium10Which load balancing algorithm in SD-WAN distributes new sessions based on the source and destination IP addresses, ensuring that all sessions from a given source-destination pair go to the same member?
Easy11What is the purpose of BFD on a FortiGate?
Easy12An administrator wants to load balance traffic across two WAN links by session count. Which SD-WAN load balancing algorithm should they use?
Easy13An administrator wants to ensure that traffic from a specific source IP uses a particular SD-WAN member regardless of performance SLA results. Which SD-WAN configuration element should be used?
Medium14An administrator is configuring an SD-WAN rule on a FortiGate. They want to load balance traffic across three WAN links based on the volume of traffic sent. Which load balancing algorithm should they use?
Easy15A FortiGate has multiple VRFs configured. An administrator wants to allow traffic from VRF 1 to reach a server in VRF 2. What configuration is required?
Medium16An administrator runs 'diagnose sys session filter dport 443' and sees: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?
Medium17A FortiGate has multiple equal-cost routes to the same destination via two different interfaces. ECMP load balancing is enabled. What determines how traffic is distributed among the routes?
Medium18A network administrator configures an SD-WAN zone with two members (port1 and port2) and sets the load balancing algorithm to 'spillover'. The spillover threshold is set to 100 Mbps on port1. If traffic reaches 120 Mbps on port1, what happens to new sessions?
Medium19An administrator wants to ensure that voice traffic (UDP 16384-32768) always uses the MPLS link, while internet-bound traffic uses broadband. Which SD-WAN feature should be configured to achieve this?
Easy20An administrator is configuring a FortiGate for SD-WAN and wants to ensure that outgoing traffic from the internal network is distributed across two WAN links based on the number of active sessions. Which SD-WAN load balancing algorithm should be used?
Easy21A FortiGate administrator wants to use BFD to quickly detect link failures in an SD-WAN deployment. Which statement about BFD configuration on FortiGate is correct?
Easy22A company has two internet connections: a primary fiber link (port1, 100 Mbps) and a backup DSL link (port2, 20 Mbps). They are using SD-WAN to load balance traffic based on volume, with a rule that sends 70% of traffic to port1 and 30% to port2. Recently, users report that video conferencing applications are experiencing high latency and jitter. The network team finds that the SD-WAN performance SLA for the fiber link shows 80% packet loss and high latency. The SD-WAN rule action is set to 'best quality' with a latency threshold of 150 ms. The current latency on port1 is 200 ms, and on port2 is 40 ms. What should the administrator do to ensure that video conferencing traffic uses the DSL link while the fiber link is degraded?
Easy23A FortiGate has two equal-cost paths to a destination network through two different ISPs. The administrator wants to load balance traffic across both links using ECMP, but notices that all traffic uses only one link. What should the administrator check first?
Medium24An administrator is configuring an SD-WAN rule to route traffic to a specific destination through a preferred member, but wants to ensure that if that member fails, traffic automatically switches to another member. Which SD-WAN rule configuration setting should they use to define the order of member preference?
Easy25A FortiGate is configured with an SD-WAN rule using 'spillover' algorithm. The primary member has a spillover threshold of 100 Mbps. Traffic of 80 Mbps is currently flowing through the primary member. A new session requiring 30 Mbps arrives. What will happen?
Hard26A FortiGate administrator wants to enable load balancing for equal-cost paths to the same destination. The FortiGate has two equal-cost routes via two different next-hop routers. Which feature should the admin enable to load balance traffic across both paths?
Easy27A FortiGate with SD-WAN configured has a Performance SLA monitoring Google DNS (8.8.8.8). The SLA is configured with latency threshold 100 ms and jitter threshold 20 ms. The link is currently meeting both thresholds. The administrator wants to ensure that if the SLA fails, traffic moves to another link. Which SD-WAN rule strategy should be used?
Medium28An administrator configures a performance SLA for SD-WAN health checks. The SLA uses a ping probe to 8.8.8.8 every 2 seconds with a latency threshold of 150 ms and jitter threshold of 20 ms. After some time, the SD-WAN rule still shows the member as 'dead'. Which command should the administrator use to verify the probe results?
Medium29What is the purpose of a route map when used with route redistribution on a FortiGate?
Easy30A network administrator is configuring SD-WAN on a FortiGate. They have multiple WAN links and want to ensure that traffic for a critical application uses the link with the lowest latency. Which SD-WAN configuration component should be used to achieve this?
Medium31A FortiGate is configured with ECMP load balancing. What is the default behavior when multiple routes have equal cost?
Easy32An administrator configures an SD-WAN rule to steer traffic from a specific subnet to an SD-WAN member with the lowest cost. Which load balancing algorithm should be selected in the SD-WAN rule to achieve this behavior?
Medium33Which routing technique allows a FortiGate to forward packets based on source IP address, destination IP address, or other criteria, in addition to the destination IP alone?
Easy34A FortiGate is configured with OSPF and BGP. The administrator wants to redistribute OSPF routes into BGP. Which TWO steps are required?
Medium35A FortiGate is configured with two SD-WAN members (wan1, wan2) and a performance SLA for each. The SD-WAN rule uses 'Maximize Bandwidth' strategy with volume-based load balancing. The administrator notices that traffic is only using wan1, even though both links have capacity. The SLA status for wan2 shows 'alive'. What could be the problem?
Hard36An administrator is configuring an SD-WAN rule to route VoIP traffic over the most reliable link. The performance SLA monitors latency, jitter, and packet loss. The administrator wants the rule to select the member with the lowest jitter that also meets the SLA thresholds. Which SD-WAN strategy should be used?
Easy37What is the purpose of a prefix list in FortiGate routing?
Easy38An administrator is configuring an SD-WAN rule to route VoIP traffic over the most reliable link. They have two WAN members: port1 (MPLS) and port2 (Internet). They create a performance SLA that monitors latency and jitter, and set the SLA target to 150 ms latency and 30 ms jitter. They apply the SLA to both members. The SD-WAN rule is set to 'Best Quality' strategy. After applying the configuration, they notice that VoIP traffic is sometimes routed over port2 even though port1 has lower latency and jitter. What is the most likely reason?
Medium39You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?
Hard40A FortiGate is configured with two VRF instances: VRF10 (for a customer) and VRF20 (for another customer). Each VRF has its own interfaces and routing table. The administrator wants to allow a specific server in VRF10 (10.10.10.5) to be reachable from a host in VRF20 (20.20.20.5) without leaking all routes between VRFs. Which FortiGate feature should be used to achieve this?
Hard41An administrator configures BFD on a FortiGate to improve convergence time for OSPF. What is the primary purpose of BFD in this context?
Medium42A FortiGate is configured with two SD-WAN members: port1 and port2. The administrator wants to ensure that voice traffic uses port1, but if port1's latency exceeds 150 ms, voice traffic should fail over to port2. Which configuration is required to achieve this?
Hard43An administrator is configuring an SD-WAN rule to distribute traffic across two WAN links based on the number of active sessions. They want to ensure that new sessions are assigned to the link with the fewest current sessions. Which load balancing algorithm should they use?
Easy44An administrator has configured an SD-WAN zone named 'virtual-wan-link' with two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'SLA1' is created and assigned to the zone. The administrator wants to ensure that SD-WAN rules use the SLA results to select the best member. Which statement correctly describes how the FortiGate uses the performance SLA results in SD-WAN rule selection?
Medium45A FortiGate is configured with two SD-WAN members (port1 and port2). The administrator sets an SD-WAN rule with 'set load-balance-mode source-dst-ip' for all internal traffic. The source IP is 10.0.0.1 and destination IP is 172.16.0.1. Which factor determines the outgoing interface for this traffic?
Medium46An administrator runs 'get router info bgp summary' and sees that the BGP session to a neighbor is in the 'Idle' state. The neighbor IP is reachable via ping. The BGP configuration uses loopback interfaces with 'update-source loopback1'. What is the MOST likely reason for the Idle state?
Hard47What is the function of a VRF (Virtual Routing and Forwarding) on a FortiGate?
Easy48An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links based on the source IP address of the traffic. Which load balancing algorithm should be used to achieve this?
Easy49A company with a hub-and-spoke SD-WAN topology uses FortiGates at each site. The hub has two WAN links: MPLS (10 Mbps) and broadband (100 Mbps). The spokes connect only via MPLS. The company deploys a new real-time application that requires low latency and low jitter. The network administrator creates an SD-WAN rule for this application with 'best quality' strategy and both MPLS and broadband as members. The SLA for MPLS is configured with latency < 10 ms and jitter < 5 ms. The SLA for broadband is configured with latency < 50 ms and jitter < 20 ms. The actual measured latency on MPLS is 12 ms, and jitter is 4 ms. The broadband latency is 25 ms, jitter 10 ms. Which path will the application traffic take?
Medium50You want to use policy-based routing (PBR) to send traffic from a specific subnet to a different next-hop than the default route. Which configuration is required?
Medium51An administrator configures a route map on a FortiGate to redistribute connected routes into OSPF. The route map sets a metric of 100. After applying, the redistributed routes appear with metric 20. What is the most likely reason?
Medium52A FortiGate is configured with VRF. Which statement about VRF is true?
Medium53An administrator is troubleshooting an SD-WAN deployment where traffic is not being forwarded according to the configured SD-WAN rules. The FortiGate has two WAN interfaces, port1 and port2, both members of an SD-WAN zone. A performance SLA is configured and both members are within SLA. The administrator suspects that the SD-WAN rules are not being evaluated correctly. Which two statements about SD-WAN rule evaluation are correct? (Choose two.)
Hard54You are troubleshooting BFD on a FortiGate SD-WAN deployment. BFD is configured on two WAN interfaces (wan1, wan2) with a minimum transmit interval of 100 ms and a multiplier of 3. The network experiences occasional jitter causing packet loss. After a brief outage, the BFD session does not recover. Which setting should be adjusted to improve BFD resilience without significantly increasing failover time?
Hard55An administrator has deployed a FortiGate at a branch with two WAN links: port1 (primary) and port2 (backup). They create an SD-WAN zone and a performance SLA named 'ISP-Health' that monitors 8.8.8.8 using ping. The SLA is configured with link-cost-factor latency and a threshold of 50 ms. After a week, they notice that the primary link is still being used for all traffic even though its latency frequently exceeds 150 ms. The backup link has 20 ms latency. What is the most likely reason the SD-WAN rule is not failing over?
Medium56Which FortiGate feature allows the creation of multiple virtual routing tables within a single VDOM?
Easy57A FortiGate is configured with ECMP load balancing for equal-cost routes. The administrator wants to ensure that all traffic from a specific source IP uses the same next hop. Which ECMP load balancing method should be selected?
Medium58A FortiGate is configured with BGP and OSPF. The administrator wants to ensure that routes learned via BGP are redistributed into OSPF, but only specific prefixes. Which three components are needed? (Select THREE.)
Hard59An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links. The administrator wants to distribute traffic based on the source IP address to ensure that each source uses a consistent path. Which load balancing algorithm should be used?
Easy60What is the purpose of configuring BFD (Bidirectional Forwarding Detection) on a FortiGate?
Easy61A FortiGate is configured with ECMP load balancing for multiple equal-cost routes. The administrator wants to ensure that all packets belonging to the same session go out the same interface. Which ECMP load balancing method should be used?
Hard62A FortiGate with SD-WAN has two members: MPLS (port1) and Broadband (port2). The performance SLA is configured to monitor latency and packet loss. The administrator notices that after a brief outage on the MPLS link, traffic fails over to Broadband but does not fail back when MPLS recovers. What is the likely cause?
Medium63An administrator has configured BGP on a FortiGate with two upstream ISPs. They notice that traffic to a specific prefix is not load-balanced as expected; all traffic goes through ISP1 even though both paths are available. 'get router info bgp network' shows the prefix with two next hops. What is the MOST likely cause?
Hard64An administrator has configured a FortiGate with an SD-WAN zone named 'virtual-wan-link' containing two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'CriticalSLA' monitors a server at 8.8.8.8 using ICMP probes every 5 seconds, with failure thresholds: latency 200 ms, jitter 50 ms, packet loss 5%. The SLA status for port1 is 'alive' and for port2 is 'dead'. An SD-WAN rule is configured to use the 'lowest-cost' algorithm with the SLA target 'CriticalSLA'. The administrator notices that all traffic is being routed through port1, even though port2 has a lower cost metric. What is the most likely reason for this behavior?
Medium65What is the purpose of using a prefix list in route redistribution?
Easy66An administrator needs to configure an SD-WAN rule that routes traffic from the guest VLAN to the Internet using the most cost-effective link. The SD-WAN zone contains three members: port1 (MPLS, cost 10), port2 (Broadband, cost 5), and port3 (LTE, cost 20). All members meet the performance SLA. Which load balancing algorithm should be used to ensure traffic uses the lowest-cost link?
Easy67A network administrator is configuring SD-WAN on a FortiGate. The organization has two internet links: MPLS (primary) and broadband (backup). The administrator wants all traffic to use the MPLS link unless it fails, in which case traffic should fail over to the broadband link. Which SD-WAN configuration best achieves this requirement?
Easy68Which of the following is the primary purpose of BFD (Bidirectional Forwarding Detection) on a FortiGate?
Easy69An administrator configures BFD on a BGP session between two FortiGates. After enabling BFD, the BGP session flaps intermittently. What is the most likely cause?
Hard70An administrator sees the following output from 'get router info routing-table': S 0.0.0.0/0 [10/0] via 192.168.1.1, port1 S 0.0.0.0/0 [10/0] via 192.168.2.1, port2 They have configured ECMP load balancing. However, traffic to a specific destination IP is always using port1. What is the likely reason?
Medium71Which SD-WAN load balancing algorithm distributes traffic based on the number of active sessions per SD-WAN member?
Easy72An administrator is integrating a FortiExtender with a FortiGate. The FortiExtender is connected to port5 and configured with a cellular WAN connection. What must be configured on the FortiGate to allow the FortiExtender to provide WAN connectivity as an SD-WAN member?
Hard73A FortiGate is running OSPF with multiple areas. The admin wants to redistribute a static route for 192.168.100.0/24 into OSPF. After configuring 'config router ospf' with 'redistribute static' enabled, the route appears in the OSPF database but is not being advertised to other areas. What is the most likely cause?
Hard74An administrator needs to configure VRF to separate traffic for two departments. Which TWO components must be configured for each VRF?
Medium75A FortiGate is deployed with two ISPs and SD-WAN. The organization uses OSPF to exchange routes with a remote branch. The administrator notices that the FortiGate is not installing OSPF-learned routes into the routing table. The OSPF configuration is verified to be correct, and neighbors are established. Which configuration could be causing the issue?
Hard76An administrator is troubleshooting an SD-WAN rule that is not matching traffic as expected. The rule is configured with a source address of 'all', destination '10.0.0.0/24', and service 'HTTP'. The rule is placed after a rule that matches all traffic to '10.0.0.0/24' with service 'ALL'. The administrator notices that HTTP traffic to 10.0.0.0/24 is being handled by the first rule. What is the most likely cause?
Hard77An administrator configures a prefix list to filter routes received from a BGP neighbor. The prefix list permits 192.168.0.0/16 le 24. Which routes are permitted?
Medium78A network administrator needs to configure SD-WAN on a FortiGate to distribute traffic across two WAN links based on session count. Which load balancing algorithm should be selected in the SD-WAN rule?
Easy79A network admin needs to configure a FortiGate to load balance traffic across two ISP links using SD-WAN. The requirement is to use both links simultaneously for different sessions based on source-destination IP hash. Which two settings are required? (Select TWO.)
Medium80A FortiGate is configured with two VRF instances: VRF10 (for the finance department) and VRF20 (for the engineering department). Each VRF has its own routing table and interfaces. The administrator needs to allow a server in VRF10 (10.10.10.10) to communicate with a server in VRF20 (10.20.20.20). The administrator has already configured the necessary firewall policies to allow the traffic. However, pings from 10.10.10.10 to 10.20.20.20 fail. What is the most likely cause?
Hard81An administrator is configuring an SD-WAN rule to prefer a specific overlay tunnel for VoIP traffic. The rule uses the 'SLA' strategy with a performance SLA that measures jitter and latency. After applying the rule, the administrator notices that VoIP traffic is still being routed over a different member that does not meet the SLA. What is the most likely cause?
Medium82You run 'diagnose sys session filter dport 179' on a FortiGate and see many sessions with proto=6 and proto_state=01. What does this indicate about the BGP sessions?
Hard83Which FortiGate feature is used to detect link failures within milliseconds, allowing rapid convergence for routing protocols like OSPF and BGP?
Easy84Which routing protocol is commonly used in SD-WAN deployments to exchange routes between FortiGate and the provider edge router in an MPLS network?
Easy85Which feature allows a FortiGate to participate in multiple routing tables simultaneously, enabling network segmentation and overlapping IP address spaces?
Easy86An administrator is troubleshooting SD-WAN and runs the following CLI command: 'execute sdwan-health-check status' The output shows that one SD-WAN member has a status of 'dead'. What does this indicate?
Medium87A network administrator is troubleshooting an SD-WAN setup where a specific application is not using the intended overlay tunnel. The SD-WAN rule is configured with a destination of 'all' and a source of 'all', and the strategy is set to 'manual' with the overlay tunnel as the preferred member. However, traffic is still going out via the underlay. What is the most likely reason?
Medium88An administrator is configuring an SD-WAN rule that uses the 'volume' load balancing algorithm. The rule includes two members: port1 with a volume ratio of 3, and port2 with a volume ratio of 1. Which two statements correctly describe how the FortiGate will distribute sessions? (Choose two.)
Medium89An administrator wants to integrate a FortiExtender into an existing SD-WAN deployment. Which TWO steps are required for proper integration?
Medium90An administrator has an SD-WAN deployment with two members, port1 (primary, low latency) and port2 (secondary, high latency). A performance SLA is configured using a ping probe to 8.8.8.8 with a 100 ms latency threshold. The SLA status for port1 is 'alive' and for port2 is 'dead'. The administrator creates an SD-WAN rule with the 'SLA' strategy that includes both members. They expect traffic to use port1 and, if it fails, port2. However, after applying the rule, all traffic is still going out port1 and never uses port2. What is the cause of this behavior?
Medium91What is the function of a route map in FortiGate routing?
Easy92An administrator has deployed a FortiGate in an SD-WAN hub-and-spoke topology. Spoke sites use IPsec tunnels to the hub, and the hub advertises a default route to the spokes. The administrator wants traffic from any spoke to another spoke to flow through the hub without requiring additional tunnels between spokes. Which SD-WAN feature should be configured on the hub to achieve this?
Medium93An administrator wants to verify which SD-WAN member is currently being used for a specific traffic flow. Which command should they use on the FortiGate?
Easy94A FortiGate with two WAN interfaces configured in an SD-WAN setup uses the 'lowest-cost' load balancing algorithm. The performance SLA monitors latency and jitter. If wan1 has a cost of 10 and wan2 has a cost of 20, but wan1 is experiencing 50% packet loss, what will happen to traffic?
Hard95A FortiGate has two WAN interfaces (port1, port2) as SD-WAN members. The performance SLA monitor is configured for both with a latency threshold of 50 ms. The measured latency on port1 is 45 ms and on port2 is 55 ms. An SD-WAN rule uses 'lowest-cost' algorithm. Which interface will be selected for new sessions?
Hard96A FortiGate is running OSPF with multiple areas. The admin wants to redistribute a static route (192.168.100.0/24) into OSPF area 0. The route is configured as a static route on the FortiGate. Which configuration step is essential to ensure the static route is redistributed into OSPF?
Hard97An administrator is configuring an SD-WAN rule to route VoIP traffic (identified by application 'VoIP') over the best available link. The SD-WAN zone 'virtual-wan-link' contains three members: port1 (cost 10), port2 (cost 20), and port3 (cost 30). A performance SLA named 'VoIP-SLA' is applied to the rule, monitoring latency, jitter, and packet loss. The administrator wants the rule to select the member with the lowest latency that meets the SLA. Which SD-WAN algorithm should be used?
Hard98A network administrator is configuring SD-WAN rules with load balancing. They want to distribute HTTP traffic evenly across two WAN links based on the number of sessions. Which TWO settings should they use? (Choose two.)
Medium99A FortiGate has an SD-WAN rule with two members: port1 and port2. The rule uses the 'lowest-cost' algorithm. The administrator configures a performance SLA that monitors latency to a remote server. The SLA is applied to both members. After some time, port1's latency exceeds the SLA threshold and its status becomes 'dead'. What happens to new sessions that match the SD-WAN rule?
Hard100An administrator wants to ensure that all traffic from a specific LAN subnet (192.168.10.0/24) to the internet uses a particular WAN interface (wan1) in an SD-WAN setup, while other traffic uses wan2. What is the correct configuration to achieve this?
Medium101An administrator has configured a FortiGate with two VRF instances: VRF10 and VRF20. They need to allow a server in VRF10 (10.10.10.0/24) to communicate with a server in VRF20 (10.20.20.0/24). The administrator creates a firewall policy with source interface VRF10 and destination interface VRF20, but traffic is not passing. What is the most likely cause?
Hard102Which FortiGate feature allows multiple independent routing tables on a single device, enabling traffic separation for different departments or customers?
Easy103A network administrator is configuring SD-WAN on a FortiGate and wants to ensure that VoIP traffic uses the link with the lowest latency while bulk download traffic uses the link with the highest bandwidth. Which TWO configuration steps are required?
Medium104A FortiGate has two WAN interfaces configured as SD-WAN members. The administrator wants traffic to specific destination IP addresses to use a particular member. Which SD-WAN configuration object should be used to achieve this?
Medium105Drag and drop the steps to configure a FortiGate to use an external authentication server (e.g., RADIUS) for admin login into the correct order.
Medium106Which THREE statements are true about FortiGate SD-WAN health-check configuration?
Medium107An administrator configures OSPF on a FortiGate with multiple areas. After configuration, the FortiGate does not become an ABR. What is the most likely reason?
Hard108Which load balancing algorithm in SD-WAN sends new sessions to the member interface with the least number of active sessions?
Easy109Which SD-WAN load balancing algorithm distributes traffic based on the number of active sessions per interface?
Easy110Which SD-WAN load balancing algorithm distributes new sessions based on the number of active sessions on each link?
Easy111A FortiGate with FortiExtender is using LTE as a backup WAN link. When the primary link fails, the LTE link does not take over. What could be the cause?
Hard112An administrator configures SD-WAN with two members (wan1, wan2) and a performance SLA for ICMP to 1.1.1.1. The SD-WAN rule is set to 'Best Quality' with 'latency' metric. The admin notices that traffic sometimes switches to the other link even when the current link has acceptable latency. Which action can reduce unnecessary flapping?
Medium113A FortiGate is configured with OSPF multi-area. The administrator wants to ensure that routes from area 0 are redistributed into area 1. Which OSPF configuration is required?
Easy114A FortiGate is configured with two SD-WAN members: port1 and port2, both with the same cost. An SD-WAN rule is set to use the 'lowest-cost (SLA)' strategy. The administrator observes that all traffic is going out port1, even though port2 is also within SLA. What is the most likely reason?
Hard115An administrator has configured an SD-WAN rule with the 'lowest-cost' strategy. The rule includes two members: port1 and port2. The administrator notices that all traffic is being sent over port1, even though port2 has a lower latency. Which factor is most likely causing this behavior?
Medium116A FortiGate is configured with two WAN interfaces in an SD-WAN zone. The administrator wants to ensure that Voice over IP (VoIP) traffic uses the link with the lowest latency, while all other traffic uses the link with the highest available bandwidth. The performance SLA 'VoIP_SLA' monitors latency to a VoIP provider. Which SD-WAN configuration should the administrator implement to meet these requirements?
Medium117A FortiGate has two equal-cost paths to a destination network. ECMP is enabled. The administrator notices that all traffic uses the first path. What is the most likely cause?
Hard118A FortiGate with SD-WAN enabled uses two members: MPLS (10 ms latency) and Internet (40 ms latency). The SD-WAN rule uses 'Best Quality' strategy with latency as the metric. Traffic to a critical application (10.1.1.0/24) is currently using the MPLS link. The MPLS link's latency increases to 60 ms due to a routing issue. How will FortiGate handle new sessions to 10.1.1.0/24?
Medium119An administrator has configured an SD-WAN zone named 'virtual-wan' containing two members: port1 and port2. They want to apply different SD-WAN rules based on the destination IP address. Which FortiGate configuration object should they use to define the destination IP address for matching traffic in an SD-WAN rule?
Medium120An administrator is troubleshooting BGP with SD-WAN. They have configured BGP on the FortiGate and the SD-WAN rule uses 'best quality' strategy. However, failover does not happen when a WAN link goes down. The BGP session is still up. What is the most likely reason?
Medium121A FortiGate is configured with SD-WAN using load balancing algorithm 'source-dest-ip'. What is the primary characteristic of this algorithm?
Easy122An administrator needs to apply different routing policies for traffic based on source IP address, overriding the normal routing table. Which feature should be configured?
Medium123A FortiGate is configured with two SD-WAN members: port1 (WAN1) and port2 (WAN2). An SD-WAN rule routes traffic from the internal subnet 10.0.1.0/24 to the internet using the 'volume' load-balancing algorithm. The rule is configured with a volume ratio of 70:30 for port1:port2. After some time, the administrator notices that port1 is handling approximately 90% of the traffic volume, while port2 handles only 10%. What is the most likely cause of this imbalance?
Medium124A FortiGate is configured with two WAN members in an SD-WAN zone. The performance SLA monitors latency to a probe server. The rule uses 'best quality' strategy. After some time, one member fails the SLA. Which action does the FortiGate take for existing sessions that were using that member?
Hard125A FortiGate administrator is integrating a FortiSwitch managed by the FortiGate. They want to configure a VLAN interface on the FortiSwitch for user traffic. Which configuration is required on the FortiGate?
MediumOther domains
All NSE7 exam domains
Frequently asked questions
- What does the Advanced Networking and SD-WAN domain cover on the NSE7 exam?
- Be able to select the right FortiGate feature for a routing scenario and predict the resulting routing-table entry. The single most important thing: know when policy routes, VRFs, BFD, or OSPF redistribution apply, and how each changes route selection and convergence.
- How many questions are in this domain?
- This page lists all 125 Advanced Networking and SD-WAN questions in the NSE7 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Advanced Networking and SD-WAN questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.