How to Add a FortiExtender as an SD-WAN Member on FortiGate
An administrator wants to integrate a FortiExtender with a FortiGate to provide cellular WAN connectivity. Which configuration step is required on the FortiGate to use the FortiExtender as an SD-WAN member?
⚠ Common exam trap
Many exam-takers confuse the need for a firewall policy or static route with the SD-WAN membership requirement, but the FortiGate treats the FortiExtender interface as a local interface, so only adding it to the SD-WAN zone is necessary for SD-WAN participation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the FortiExtender's interface to the SD-WAN zone
To use a FortiExtender as an SD-WAN member, the FortiExtender's physical or logical interface must be added to the SD-WAN zone on the FortiGate. This allows the FortiGate to apply SD-WAN rules, load balancing, and SLA-based path selection to traffic traversing the cellular WAN link. Without this step, the interface remains a standard WAN interface and cannot participate in SD-WAN policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable BGP on the FortiExtender interface
Why it's wrong here
BGP is a dynamic routing protocol for exchanging prefixes between peers; it does not register the FortiExtender interface as an SD-WAN member on the FortiGate. It is tempting because BGP is genuinely used in SD-WAN deployments to advertise and learn routes across multiple WAN links.
- ✗
Create a firewall policy allowing traffic from the FortiExtender
Why it's wrong here
A firewall policy governs traffic forwarding, not SD-WAN membership; the FortiExtender must first be authorised and its interface added as an SD-WAN member. It is tempting because policies are genuinely required for cellular traffic to pass once the extender is integrated as a WAN link.
- ✓
Add the FortiExtender's interface to the SD-WAN zone
Why this is correct
SD-WAN selects members from interfaces assigned to the SD-WAN zone. Adding the FortiExtender's interface to that zone makes it eligible for SD-WAN rules and health checks, enabling cellular WAN participation in load balancing and failover.
- ✗
Configure a static route pointing to the FortiExtender
Why it's wrong here
A static route only directs traffic toward a next hop; it does not enrol the FortiExtender interface into the SD-WAN member list, which is the actual prerequisite. It is tempting because static routes are genuinely used to steer traffic over a cellular WAN link after membership is configured.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.