Mastering SD-WAN Overlay Design
30 Questions
1 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which type of tunnel is set to static and known in the IPsec configuration for the spoke?

  • Static; dial-up client (correct)
  • Dynamic; dial-up client
  • Static; dial-up server
  • Dynamic; dial-up server
  • What is the purpose of enabling the net-device setting in SD-WAN?

  • To increase the number of overlays deployed
  • To enhance security
  • To support AD-VPN shortcuts (correct)
  • To improve performance
  • What is the configuration of the phase2 in the spoke?

  • Not mentioned in the text
  • Depends on the overlay
  • The same as in the hub (correct)
  • Different from the hub
  • What is the encryption domain in the spoke configuration?

    <p>Open to all traffic</p> Signup and view all the answers

    What is the purpose of assigning an IP-address for the overlays in the spoke configuration?

    <p>To obtain an IP-address using IKE mode configuration</p> Signup and view all the answers

    Which port is the tunnel bound to in the spoke configuration?

    <p>port1</p> Signup and view all the answers

    What is the purpose of allowing ping in the spoke configuration?

    <p>To monitor network performance</p> Signup and view all the answers

    How many overlays are usually deployed on the spokes?

    <p>A small number</p> Signup and view all the answers

    What zone are the two overlays placed in the SD-WAN configuration for the spokes?

    <p>Overlay zone</p> Signup and view all the answers

    What is the main focus of the IPsec configuration for the spoke in this lesson?

    <p>Settings specific to the spoke</p> Signup and view all the answers

    Which IP address is used to measure the health and performance of the overlays?

    <p>10.200.99.1</p> Signup and view all the answers

    What is the purpose of the VPN performance SLA?

    <p>To determine the best quality member in the overlay zone</p> Signup and view all the answers

    What are the default values for the BGP timers?

    <p>Keep alive: 60 seconds, Hold: 180 seconds, Advertysement: 30 seconds</p> Signup and view all the answers

    What does reducing the advertysement interval in BGP configuration help with?

    <p>Speeding up routing convergence</p> Signup and view all the answers

    What does enabling link down failover feature in BGP configuration do?

    <p>Brings down peerings immediately after the interface they use comes down</p> Signup and view all the answers

    What are the default values for the IPsec DPD settings?

    <p>Retry count: 3, Retry interval: 20 seconds</p> Signup and view all the answers

    What is the purpose of overlay stickiness on the hub?

    <p>To prefer spoke-to-spoke traffic to stay within the same-ISP overlays</p> Signup and view all the answers

    What happens when the hub receives the first packet of a spoke-to-spoke connection?

    <p>It performs a route lookup to determine the best route</p> Signup and view all the answers

    What is the default time it takes for DPD to detect a dead gateway?

    <p>80 seconds</p> Signup and view all the answers

    How can the time to detect a dead gateway using DPD be reduced to 30 seconds?

    <p>By setting the retry count and retry interval to 2 and 10 respectively</p> Signup and view all the answers

    Which type of traffic does FortiGate prefer to keep within same-ISP overlays in AD-VPN?

    <p>Spoke-to-spoke traffic</p> Signup and view all the answers

    What is the purpose of configuring policy routes in FortiGate for AD-VPN?

    <p>To improve performance</p> Signup and view all the answers

    When are the policy routes used in FortiGate for AD-VPN?

    <p>Only if the FIB contains a route for the outgoing overlay</p> Signup and view all the answers

    What is overlay stickiness in AD-VPN?

    <p>A preference for keeping spoke-to-spoke traffic within same-ISP overlays</p> Signup and view all the answers

    What is the main reason for the suboptimal performance in AD-VPN?

    <p>Added latency introduced by the cross-ISP overlay path</p> Signup and view all the answers

    What does the FIB stand for in FortiGate for AD-VPN?

    <p>Forwarding Information Base</p> Signup and view all the answers

    What happens if the FIB does not contain a route for the outgoing overlay in FortiGate for AD-VPN?

    <p>The policy routes are skipped and traffic is forwarded based on the best route in the FIB</p> Signup and view all the answers

    What is the purpose of overlay stickiness in AD-VPN?

    <p>To prevent spokes from negotiating shortcuts over unreachable underlays</p> Signup and view all the answers

    What is the importance of overlay stickiness in AD-VPN?

    <p>It helps prevent spokes from trying to negotiate shortcuts over unreachable underlays</p> Signup and view all the answers

    What will you learn more about in this lesson?

    <p>AD-VPN and overlay stickiness</p> Signup and view all the answers

    More Like This

    VPN Gateways
    20 questions

    VPN Gateways

    VisionarySugilite avatar
    VisionarySugilite
    IPSec Fundamentals Quiz
    10 questions

    IPSec Fundamentals Quiz

    InviolableDalmatianJasper avatar
    InviolableDalmatianJasper
    IPsec Protocol Configuration
    10 questions

    IPsec Protocol Configuration

    GuiltlessAshcanSchool avatar
    GuiltlessAshcanSchool
    Use Quizgecko on...
    Browser
    Browser