Podcast
Questions and Answers
Which type of sessions are triggered by a change in the reply traffic interface?
Which type of sessions are triggered by a change in the reply traffic interface?
- Asymmetric sessions
- Symmetric sessions
- Auxiliary sessions
- Dirty sessions (correct)
What handles dirty sessions triggered by reply interface changes?
What handles dirty sessions triggered by reply interface changes?
- Symmetric sessions
- System CPU (correct)
- FortiGate VMs
- Hardware offload
Why is hardware offloading not used for dirty sessions triggered by reply interface changes?
Why is hardware offloading not used for dirty sessions triggered by reply interface changes?
- To improve performance (correct)
- To offload asymmetric sessions
- To prevent high CPU utilization
- To preserve session symmetry
What is the default behavior for route lookup of reply traffic?
What is the default behavior for route lookup of reply traffic?
What prevents reply traffic from switching to a better performing member?
What prevents reply traffic from switching to a better performing member?
What are auxiliary sessions also known as?
What are auxiliary sessions also known as?
What is the purpose of auxiliary sessions?
What is the purpose of auxiliary sessions?
What is the benefit of using auxiliary sessions for FortiGate VMs?
What is the benefit of using auxiliary sessions for FortiGate VMs?
What can result from a huge amount of traffic handled by dirty sessions?
What can result from a huge amount of traffic handled by dirty sessions?
Why is a change in the reply traffic interface often seen in SD-WAN?
Why is a change in the reply traffic interface often seen in SD-WAN?
Which FortiGate device routes the reply traffic over port1 in the original direction?
Which FortiGate device routes the reply traffic over port1 in the original direction?
What happens when auxiliary sessions are enabled on both FortiGate devices?
What happens when auxiliary sessions are enabled on both FortiGate devices?
How can you enable auxiliary sessions per V-Dom on the FortiGate CLI?
How can you enable auxiliary sessions per V-Dom on the FortiGate CLI?
What does the debug flow sample on FGT-1 show when an auxiliary session is created for an SSH connection?
What does the debug flow sample on FGT-1 show when an auxiliary session is created for an SSH connection?
What is an auxiliary session?
What is an auxiliary session?
How can you reference a member in a firewall policy?
How can you reference a member in a firewall policy?
What does the underlay zone contain in the example firewall policy?
What does the underlay zone contain in the example firewall policy?
What can firewall policy changes lead to?
What can firewall policy changes lead to?
Which sessions are flagged as dirty when the 'check-all' option is enabled?
Which sessions are flagged as dirty when the 'check-all' option is enabled?
How do you configure SD-WAN firewall policies?
How do you configure SD-WAN firewall policies?
Which setting instructs FortiGate to flag all sessions as dirty when a change is made to a firewall policy?
Which setting instructs FortiGate to flag all sessions as dirty when a change is made to a firewall policy?
What is the purpose of flagging sessions as dirty when a change is made to a firewall policy?
What is the purpose of flagging sessions as dirty when a change is made to a firewall policy?
What can be done to prevent high CPU utilization when a firewall policy change impacts a large number of sessions?
What can be done to prevent high CPU utilization when a firewall policy change impacts a large number of sessions?
When is the firewall-session-dirty setting evaluated?
When is the firewall-session-dirty setting evaluated?
What does the presence of the persistent flag in a session indicate?
What does the presence of the persistent flag in a session indicate?
What is the default value for the firewall-session-dirty setting?
What is the default value for the firewall-session-dirty setting?
When can the firewall policy-level setting be used?
When can the firewall policy-level setting be used?
What does the may_dirty flag indicate?
What does the may_dirty flag indicate?
What is the purpose of the V-Dom-level setting?
What is the purpose of the V-Dom-level setting?
What does the check-policy-option value for the V-Dom-level setting indicate?
What does the check-policy-option value for the V-Dom-level setting indicate?
Flashcards are hidden until you start studying