ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 11 - NSE7_EFW-7.2 discussion

Report
Export

Which two statements about ADVPN are true? (Choose two.)

A.
You must disable add-route in the hub.
Answers
A.
You must disable add-route in the hub.
B.
AllFortiGate devices must be in the same autonomous system (AS).
Answers
B.
AllFortiGate devices must be in the same autonomous system (AS).
C.
The hub adds routes based on IKE negotiations.
Answers
C.
The hub adds routes based on IKE negotiations.
D.
You must configure phase 2 quick mode selectors to 0.0.0.0 0.0.0.0.
Answers
D.
You must configure phase 2 quick mode selectors to 0.0.0.0 0.0.0.0.
Suggested answer: C, D

Explanation:

C) The hub adds routes based on IKE negotiations: This is part of the ADVPN functionality where the hub learns about the networks behind the spokes and can add routes dynamically based on the IKE negotiations with the spokes.

You must configure phase 2 quick mode selectors to 0.0.0.0 0.0.0.0: This wildcard setting in the phase 2 selectors allows any-to-any tunnel establishment, which is necessary for the dynamic creation of spoke-to-spoke tunnels. These configurations are outlined in Fortinet's documentation for setting up ADVPN, where the hub's role in route control and the use of wildcard selectors for phase 2 are emphasized to enable dynamic tunneling between spokes.


asked 18/09/2024
Perry Schoenmaker
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first