Module 5 ZTNA Flashcards
(17 cards)
Where do endpoints get device certificates from?
From FortiSASE CA when it first connects.
What does the FortiSASE CA use to sign the cert?
FortiClient unique ID
Certificate serial number
and FortiSASE. EMS SN
How does FortiGate connect to EMS?
FortiClient EMS cloud fabric connector
Do you have to register FortiSASE and Fortigate under the same FortiCloud account?
Yes
True or false you do not have to install the FortiSASE EMS server cert onto FTG
False
True or false you must authorize FTG in FortiSASE
True
What operating Systems Can have a Tagging rule applied to them?
Windows,
MacOS
Linux.
iOS
Andriod
Is ZTNA visible on FTG by default?
No
What command do you enter to enable ZTNA on entry-level models?
Config system global
set prox-and-explicit-proxy enable
What is the default routing design method for FortiSASE
BGP per overlay
IBGP session terminates on tunnel ip add
Must config mode-cfg on hub
What are the two routing design methods supported by SASE
BGP per overlay
BGP on loop back
Can you mix and match bgp routing designs?
No, all must be the same
What are the two hub selection methods
Hub health and priority
BGP-MED
What is the hub health and priority hub selection method
Health check receives
Latency <120ms
Jitter threshold 55ms
Packet los 1%
Sase selects the highest priority hub, that meets the lowest cost sla
Explain BGP MED hub selection
Discriminates amount multiple exit or entry points to the same AS
Lower the MED the more preferred the path
What is the highest priority for hubs?
P1!