Podcast
Questions and Answers
Which type of sessions are triggered by a change in the reply traffic interface?
Which type of sessions are triggered by a change in the reply traffic interface?
What handles dirty sessions triggered by reply interface changes?
What handles dirty sessions triggered by reply interface changes?
Why is hardware offloading not used for dirty sessions triggered by reply interface changes?
Why is hardware offloading not used for dirty sessions triggered by reply interface changes?
What is the default behavior for route lookup of reply traffic?
What is the default behavior for route lookup of reply traffic?
Signup and view all the answers
What prevents reply traffic from switching to a better performing member?
What prevents reply traffic from switching to a better performing member?
Signup and view all the answers
What are auxiliary sessions also known as?
What are auxiliary sessions also known as?
Signup and view all the answers
What is the purpose of auxiliary sessions?
What is the purpose of auxiliary sessions?
Signup and view all the answers
What is the benefit of using auxiliary sessions for FortiGate VMs?
What is the benefit of using auxiliary sessions for FortiGate VMs?
Signup and view all the answers
What can result from a huge amount of traffic handled by dirty sessions?
What can result from a huge amount of traffic handled by dirty sessions?
Signup and view all the answers
Why is a change in the reply traffic interface often seen in SD-WAN?
Why is a change in the reply traffic interface often seen in SD-WAN?
Signup and view all the answers
Which FortiGate device routes the reply traffic over port1 in the original direction?
Which FortiGate device routes the reply traffic over port1 in the original direction?
Signup and view all the answers
What happens when auxiliary sessions are enabled on both FortiGate devices?
What happens when auxiliary sessions are enabled on both FortiGate devices?
Signup and view all the answers
How can you enable auxiliary sessions per V-Dom on the FortiGate CLI?
How can you enable auxiliary sessions per V-Dom on the FortiGate CLI?
Signup and view all the answers
What does the debug flow sample on FGT-1 show when an auxiliary session is created for an SSH connection?
What does the debug flow sample on FGT-1 show when an auxiliary session is created for an SSH connection?
Signup and view all the answers
What is an auxiliary session?
What is an auxiliary session?
Signup and view all the answers
How can you reference a member in a firewall policy?
How can you reference a member in a firewall policy?
Signup and view all the answers
What does the underlay zone contain in the example firewall policy?
What does the underlay zone contain in the example firewall policy?
Signup and view all the answers
What can firewall policy changes lead to?
What can firewall policy changes lead to?
Signup and view all the answers
Which sessions are flagged as dirty when the 'check-all' option is enabled?
Which sessions are flagged as dirty when the 'check-all' option is enabled?
Signup and view all the answers
How do you configure SD-WAN firewall policies?
How do you configure SD-WAN firewall policies?
Signup and view all the answers
Which setting instructs FortiGate to flag all sessions as dirty when a change is made to a firewall policy?
Which setting instructs FortiGate to flag all sessions as dirty when a change is made to a firewall policy?
Signup and view all the answers
What is the purpose of flagging sessions as dirty when a change is made to a firewall policy?
What is the purpose of flagging sessions as dirty when a change is made to a firewall policy?
Signup and view all the answers
What can be done to prevent high CPU utilization when a firewall policy change impacts a large number of sessions?
What can be done to prevent high CPU utilization when a firewall policy change impacts a large number of sessions?
Signup and view all the answers
When is the firewall-session-dirty setting evaluated?
When is the firewall-session-dirty setting evaluated?
Signup and view all the answers
What does the presence of the persistent flag in a session indicate?
What does the presence of the persistent flag in a session indicate?
Signup and view all the answers
What is the default value for the firewall-session-dirty setting?
What is the default value for the firewall-session-dirty setting?
Signup and view all the answers
When can the firewall policy-level setting be used?
When can the firewall policy-level setting be used?
Signup and view all the answers
What does the may_dirty flag indicate?
What does the may_dirty flag indicate?
Signup and view all the answers
What is the purpose of the V-Dom-level setting?
What is the purpose of the V-Dom-level setting?
Signup and view all the answers
What does the check-policy-option value for the V-Dom-level setting indicate?
What does the check-policy-option value for the V-Dom-level setting indicate?
Signup and view all the answers