Podcast
Questions and Answers
Which of the following triggers a session re-evaluation on the next packet?
Which of the following triggers a session re-evaluation on the next packet?
- Firewall policy lookup
- Application detection
- Dirty flag (correct)
- Route lookup
What does FortiGate do if the application is not detected on a packet?
What does FortiGate do if the application is not detected on a packet?
- Drops the packet
- Sends the packet to IPS for application detection (correct)
- Stores the packet in the cache
- Forwards the packet without further inspection
How many entries can the ISDB application cache contain?
How many entries can the ISDB application cache contain?
- 256 entries
- 512 entries (correct)
- 2048 entries
- 1024 entries
What happens to old entries in the ISDB application cache when it is full?
What happens to old entries in the ISDB application cache when it is full?
What does the 'app' field indicate on the SD-WAN session?
What does the 'app' field indicate on the SD-WAN session?
What does the 'rpdb_svc_id' field indicate on the SD-WAN session?
What does the 'rpdb_svc_id' field indicate on the SD-WAN session?
When can a session initially match the wrong rule and member?
When can a session initially match the wrong rule and member?
What happens to subsequent sessions with the same 3-tuple after the application is learned?
What happens to subsequent sessions with the same 3-tuple after the application is learned?
What happens to the routing information of a session subject to S-NAT after the application is detected?
What happens to the routing information of a session subject to S-NAT after the application is detected?
What is the purpose of running 'diagnose sys sdwan internet-service-app-ctrl-list' on the FortiGate CLI?
What is the purpose of running 'diagnose sys sdwan internet-service-app-ctrl-list' on the FortiGate CLI?
Which of the following is true about the application learning phase in FortiGate?
Which of the following is true about the application learning phase in FortiGate?
What does the ISDB application cache in FortiGate map?
What does the ISDB application cache in FortiGate map?
When does FortiGate add a session 3-tuple to the ISDB application cache?
When does FortiGate add a session 3-tuple to the ISDB application cache?
What happens when a packet matches an entry in the ISDB application cache in FortiGate?
What happens when a packet matches an entry in the ISDB application cache in FortiGate?
What does FortiGate do if the 3-tuple on a packet doesn't match an entry in the ISDB application cache?
What does FortiGate do if the 3-tuple on a packet doesn't match an entry in the ISDB application cache?
What does FortiGate do after the firewall policy lookup for a packet?
What does FortiGate do after the firewall policy lookup for a packet?
What does it mean when a session is flagged as dirty in FortiGate?
What does it mean when a session is flagged as dirty in FortiGate?
How many applications can be mapped to a single 3-tuple in the ISDB application cache?
How many applications can be mapped to a single 3-tuple in the ISDB application cache?
What does FortiGate do when it receives the first packet of a session?
What does FortiGate do when it receives the first packet of a session?
What is the purpose of the application learning phase in FortiGate?
What is the purpose of the application learning phase in FortiGate?