Reply Traffic Interface and Session Handling Quiz
30 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which type of sessions are triggered by a change in the reply traffic interface?

  • Asymmetric sessions
  • Symmetric sessions
  • Auxiliary sessions
  • Dirty sessions (correct)
  • What handles dirty sessions triggered by reply interface changes?

  • Symmetric sessions
  • System CPU (correct)
  • FortiGate VMs
  • Hardware offload
  • Why is hardware offloading not used for dirty sessions triggered by reply interface changes?

  • To improve performance (correct)
  • To offload asymmetric sessions
  • To prevent high CPU utilization
  • To preserve session symmetry
  • What is the default behavior for route lookup of reply traffic?

    <p>Consider routes over original ingress interface only</p> Signup and view all the answers

    What prevents reply traffic from switching to a better performing member?

    <p>Default route lookup behavior</p> Signup and view all the answers

    What are auxiliary sessions also known as?

    <p>Reflect sessions</p> Signup and view all the answers

    What is the purpose of auxiliary sessions?

    <p>To offload asymmetric traffic to hardware</p> Signup and view all the answers

    What is the benefit of using auxiliary sessions for FortiGate VMs?

    <p>Performance is improved</p> Signup and view all the answers

    What can result from a huge amount of traffic handled by dirty sessions?

    <p>High CPU utilization and poor performance</p> Signup and view all the answers

    Why is a change in the reply traffic interface often seen in SD-WAN?

    <p>To switch to a better performing link</p> Signup and view all the answers

    Which FortiGate device routes the reply traffic over port1 in the original direction?

    <p>Both FGT-1 and FGT-2</p> Signup and view all the answers

    What happens when auxiliary sessions are enabled on both FortiGate devices?

    <p>Both FGT-1 and FGT-2 can offload the session to hardware</p> Signup and view all the answers

    How can you enable auxiliary sessions per V-Dom on the FortiGate CLI?

    <p>config system settings set auxiliary-session enable end</p> Signup and view all the answers

    What does the debug flow sample on FGT-1 show when an auxiliary session is created for an SSH connection?

    <p>The index number of the interfaces used for creating the auxiliary session</p> Signup and view all the answers

    What is an auxiliary session?

    <p>An extension of the main session used for symmetric traffic</p> Signup and view all the answers

    How can you reference a member in a firewall policy?

    <p>By placing the member in a separate zone and referencing that zone</p> Signup and view all the answers

    What does the underlay zone contain in the example firewall policy?

    <p>Port1 and port2 as members</p> Signup and view all the answers

    What can firewall policy changes lead to?

    <p>High CPU utilization</p> Signup and view all the answers

    Which sessions are flagged as dirty when the 'check-all' option is enabled?

    <p>All impacted sessions</p> Signup and view all the answers

    How do you configure SD-WAN firewall policies?

    <p>By referencing an SD-WAN zone</p> Signup and view all the answers

    Which setting instructs FortiGate to flag all sessions as dirty when a change is made to a firewall policy?

    <p>check-all</p> Signup and view all the answers

    What is the purpose of flagging sessions as dirty when a change is made to a firewall policy?

    <p>To perform a firewall policy lookup for all sessions</p> Signup and view all the answers

    What can be done to prevent high CPU utilization when a firewall policy change impacts a large number of sessions?

    <p>Set firewall-session-dirty to check-new</p> Signup and view all the answers

    When is the firewall-session-dirty setting evaluated?

    <p>When a new session is established</p> Signup and view all the answers

    What does the presence of the persistent flag in a session indicate?

    <p>A new session against the new firewall policy configuration</p> Signup and view all the answers

    What is the default value for the firewall-session-dirty setting?

    <p>check-all</p> Signup and view all the answers

    When can the firewall policy-level setting be used?

    <p>When the V-Dom-level setting is set to check-policy-option</p> Signup and view all the answers

    What does the may_dirty flag indicate?

    <p>A configuration change on the matching policy</p> Signup and view all the answers

    What is the purpose of the V-Dom-level setting?

    <p>To determine if the firewall policy-level setting can be used</p> Signup and view all the answers

    What does the check-policy-option value for the V-Dom-level setting indicate?

    <p>To follow the firewall policy-level setting</p> Signup and view all the answers

    More Like This

    Use Quizgecko on...
    Browser
    Browser