ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 9 - NSE7_EFW-7.2 discussion

Report
Export

Refer to the exhibit, which contains information about an IPsec VPN tunnel.

What two conclusions can you draw from the command output? (Choose two.)

A.
Dead peer detection is set to enable.
Answers
A.
Dead peer detection is set to enable.
B.
The IKE version is 2.
Answers
B.
The IKE version is 2.
C.
Both IPsec SAs are loaded on the kernel.
Answers
C.
Both IPsec SAs are loaded on the kernel.
D.
Forward error correction in phase 2 is set to enable.
Answers
D.
Forward error correction in phase 2 is set to enable.
Suggested answer: B, C

Explanation:

From the command output shown in the exhibit:

B) The IKE version is 2: This can be deduced from the presence of 'ver=2' in the output, which indicates that IKEv2 is being used.

C) Both IPsec SAs are loaded on the kernel: This is indicated by the line 'npu flags=0x0/0', suggesting that no offload to NPU is occurring, and hence, both Security Associations are loaded onto the kernel for processing.

Fortinet documentation specifies that the version of IKE (Internet Key Exchange) used and the loading of IPsec Security Associations can be verified through the diagnostic commands related to VPN tunnels.

asked 18/09/2024
Orenthial Johnson
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first