Routing
FCP-FGT-AD-7-6 · 24 questions
- A grid-operations engineer is configuring a new static route on the control-center FortiGate so traffic for a remote substation's management subnet goes out over the primary fibre uplink. Besides the destination subnet, which pair of parameters must the static route specify to actually forward traffic toward that substation?
- The NOC's FortiGate holds a static route for 10.20.0.0/16 out the primary fibre link to the regional aggregation site, and a second static route for 10.20.4.0/24 out the cellular backup modem, covering one specific substation inside that larger block. A workstation at the NOC sends a packet to 10.20.4.50. Which route does the FortiGate use to forward it?
- A network administrator at the utility's NOC is reviewing two static routes to the same remote substation subnet: one via the fibre interface with administrative distance 10, and one via the cellular backup interface also with administrative distance 10 but a higher priority value. How does the FortiGate use these two values differently when deciding which route to install?
- A regional utility's NOC FortiGate has specific static routes for every known substation and back-office subnet, plus a 0.0.0.0/0.0.0.0 static route pointing out the WAN interface toward the utility's upstream ISP. What role does that 0.0.0.0/0.0.0.0 entry play in the routing table?
- The utility has summarized several small substation subnets into a single /20 static route advertised toward its upstream provider. One of the smaller subnets inside that /20 is not actually in use yet. What is the purpose of adding a blackhole static route for that specific unused subnet on the FortiGate?
- The NOC FortiGate has two static routes to the same regional data-center subnet: one out primary fibre and one out a secondary fibre link from a different provider, both left at the default administrative distance and the default priority. What does the FortiGate do with traffic to that data-center subnet as a result?
- A field-services team wants all traffic sourced from the technician-laptop subnet, regardless of destination, to exit through the cellular backup link instead of the primary fibre uplink, even though the main routing table still prefers fibre for every destination. Which FortiGate routing feature is designed for this kind of source-based forwarding override?
- After the NOC team adds a policy route sending technician-VPN return traffic out a different interface than the one packets arrived on, some sessions start failing even though the policy route and firewall policy both look correct. What FortiGate mechanism is most likely dropping this traffic?
- The NOC wants the FortiGate to automatically detect when the primary fibre link to a remote substation stops passing traffic — not just when the physical interface goes down — and fail over to the cellular backup route before operators notice an outage. Which FortiGate capability is designed for this kind of active, above-layer-1 reachability check?
- While a technician's VPN session to a substation is actively transferring data over the primary fibre route, an administrator adds a new, more specific static route that would send that same destination over the cellular backup link instead. What happens to the technician's already-established session?
- An administrator configures two static routes to the same remote substation: one out the primary fibre interface with priority 0, and one out the cellular backup interface with priority 10, both at the same administrative distance. Under normal conditions, with both links up, which route forwards traffic to the substation?
- A FortiGate at a substation has a manually configured static route to the NOC's back-office subnet with administrative distance 10, and also learns a route to the same subnet dynamically with a higher administrative distance from a routing protocol. Assuming both routes have the same prefix length, which route does the FortiGate install as active in its routing table?
- The utility's routing table contains a static default route (0.0.0.0/0.0.0.0), a static route for 172.16.0.0/16 covering the whole substation network, and a static route for 172.16.8.0/22 covering one regional cluster of substations. A packet is destined for 172.16.8.100. Which route does the FortiGate select?
- The utility summarizes its entire remote-substation address space as a single route advertised toward its WAN transport provider so the provider's routers don't need dozens of individual entries. If one substation subnet inside that summary is temporarily decommissioned, why would an engineer add a blackhole route for just that subnet on the FortiGate, rather than leaving it unhandled?
- With ECMP active across the NOC's two fibre uplinks to a regional aggregation point, engineers notice that a single large file transfer only ever uses one of the two links, even though many separate sessions are spread across both. Why does ECMP behave this way for that one transfer?
- A substation's primary fibre static route has a configured link health monitor that pings a target on the far side of the NOC's aggregation router. The fibre physically stays up, but the aggregation router itself stops responding to the probe. What is the expected effect on the routing table?
- An administrator configures a policy route that forces all traffic from the back-office billing subnet out through a specific WAN interface and gateway, but that WAN interface is currently down. What happens to traffic matching the policy route while the interface is down?
- Two static routes exist for the same substation subnet: one via fibre at administrative distance 10 and priority 5, and one via cellular at administrative distance 20 and priority 1. Which route is active in the routing table under normal conditions?
- A utility's NOC uses dual WAN links to two different upstream providers, with policy routes sending traffic to certain destinations out one link while replies to other, unrelated sessions legitimately return over the other link based on the routing table each provider maintains. What is the general concern this design raises for the FortiGate's default anti-spoofing behavior?
- An engineer adds a new static route on the substation FortiGate and leaves the administrative distance field at its default value, without learning any competing route to the same destination from a dynamic routing protocol. What administrative distance does that static route receive by default?
- A substation has two egress paths to the NOC: a fibre link and a cellular modem, both terminated on the same FortiGate and both currently healthy. The utility wants outbound telemetry traffic automatically split across both links based on real-time latency and jitter measurements, rather than always preferring one link unless it fails outright. Which approach fits this requirement?
- ECMP is configured across three equal-cost fibre paths from the NOC to a shared regional hub, but monitoring shows one path consistently carries far more traffic than the other two, even though hundreds of independent sessions exist. What is the most likely explanation, assuming all three routes are correctly configured at equal distance and priority?
- An engineer deletes the only static route to a remote substation subnet entirely — not replacing it with a different route, just removing it — while a technician has an active session to a device in that subnet. What is the most accurate expectation for that already-established session?
- Summarizing everything a FortiGate considers when multiple candidate paths exist to the same substation subnet, in which order does it actually apply longest-prefix match, administrative distance, and priority to decide the active route?