According to the SD-WAN 7.6 Core Administrator study guide and the Fortinet Document Library, FortiOS maintains strict referential integrity for SD-WAN objects. An SD-WAN member interface cannot be deleted or removed from the configuration if it is still being " used " or referenced by other features.
Reference Locking: In the FortiOS GUI, the " Delete " button for an SD-WAN member is typically grayed out or an error message appears if the interface is part of an active service or monitoring tool.
Performance SLA Dependency: Performance SLAs (health checks) monitor specific member interfaces. If an interface is a participant in an SLA, it is considered " active " by the system. Therefore, a critical first step in the decommissioning process is to remove the member from all Performance SLA definitions. Once the health check is no longer polling that interface, one major reference lock is released.
Other Dependencies: While firewall policies and SD-WAN rules (service rules) also create references, the question specifies the member is " no longer used to steer traffic, " implying it may have already been removed from steering rules. However, Performance SLAs often remain active in the background, making their removal the essential next step to permit the deletion of the member itself.
Why other options are incorrect:
Option A: Moving a member between zones doesn ' t help you delete it; it just changes its logical grouping. It still remains an active SD-WAN member.
Option B: Disabling the physical interface does not remove the configuration references within the SD-WAN engine. The FortiGate will simply report the member as " Down, " but it will still exist in the configuration as a member.
Option D: In modern SD-WAN deployments, static routes usually point to the SD-WAN Zone (like virtual-wan-link) rather than individual physical interfaces. Therefore, you don ' t typically need to delete the static route to remove a single member from the zone.