Q: 2
Refer to the exhibits.
An administrator is testing application steering in SD-WAN. Before generating test traffic, the
administrator collected the information shown in the first exhibit. After generating GoToMeeting test
traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in
the second exhibit.
The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the
traffic to match rule ID 1.
Which two reasons explain why some log messages show that the traffic matched the implicit SD-
WAN rule? (Choose two.)
An administrator is testing application steering in SD-WAN. Before generating test traffic, the
administrator collected the information shown in the first exhibit. After generating GoToMeeting test
traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in
the second exhibit.
The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the
traffic to match rule ID 1.
Which two reasons explain why some log messages show that the traffic matched the implicit SD-
WAN rule? (Choose two.)Options
Discussion
A is wrong, B/C. ISDB cache and routing refresh issues make more sense here given the flow. Disagree?
B/C? The traffic matched the implicit rule because GoToMeeting wasn't recognized at session start and couldn't update after detection. Not 100% but lines up with how SD-WAN does first packet classification.
B/C. First packet didn't match ISDB app cache then couldn't update route after app detected. Makes sense for this behavior.
Probably A and D, since rule misconfiguration and missing SSL inspection are pretty common in these setups.
Be respectful. No spam.