A. It automatically offloads all BGP routing table computations directly to the FortiAnalyzer, significantly reducing the CPU load on the Hub FortiGates.
B. It completely replaces standard IPsec with proprietary Fortinet MACsec, ensuring Layer 2 encryption across the internet without any routing protocol overhead.
C. It forces the use of a single global subnet for all branch deployments, completely eliminating the need for NAT or complex IP address management planning.
D. It natively integrates ADVPN capabilities, automating the complex deployment of BGP route reflection and IPsec shortcut configurations across hubs and spokes.
Explanation:
✑ Core Concept: SD-WAN overlay template, configuration specifics for large topologies, and ADVPN[cite: 1].
✑ Analysis: Building a multi-region, dual-hub network with ADVPN manually involves hundreds of steps: configuring Phase 1/2, routing, BGP neighbor groups, route reflectors, and ADVPN shortcut parameters. The primary architectural advantage of the SD-WAN Overlay Template in FortiManager is its orchestration engine: you define the roles (Hub, Spoke) and the regions, and it automates the deployment of the entire underlying ADVPN architecture, including the necessary BGP dynamic routing and self-healing mechanisms.
Options A, B, and C describe highly inaccurate technical concepts (FortiAnalyzer does not route, MACsec is for direct physical links, and single subnets break routing).
✑ CLI /Reference: FortiManager GUI -> Device Manager -> SD-WAN -> Overlay Templates.