1. FortiSASE Administration Guide: In the section on Secure Private Access
the guide details integration with FortiGate secure SD-WAN. It states
"When a spoke (including FortiSASE) needs to send traffic to another spoke
it initially sends the traffic to the hub. The hub forwards the traffic...and also facilitates the two spokes to establish a dynamic IPsec tunnel
called a shortcut tunnel
between them. Subsequent traffic between the spokes flows through the shortcut tunnel
bypassing the hub." This confirms the process of initial routing via the hub
followed by the creation of a direct
dynamic path. (Search for "ADVPN" and "shortcut tunnel" in the FortiSASE Administration Guide for the relevant version).
2. FortiOS Administration Guide (SD-WAN Section): The ADVPN chapter explains that shortcut tunnels are created on-demand and that routes for these shortcuts are dynamically added to the routing table. This confirms that the route for the direct path described in the correct answer is dynamic. (Refer to the "ADVPN" section in the FortiOS Handbook).