ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 32 - NSE7_EFW-7.2 discussion

Report
Export

Exhibit.

Refer to the exhibit, which shows a partial touting table

What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

A.
IPSec Tunnel aggregation is configured
Answers
A.
IPSec Tunnel aggregation is configured
B.
net-device is enabled in the tunnel IPSec phase 1 configuration
Answers
B.
net-device is enabled in the tunnel IPSec phase 1 configuration
C.
OSPI is configured to run over IPSec.
Answers
C.
OSPI is configured to run over IPSec.
D.
add-route is disabled in the tunnel IPSec phase 1 configuration.
Answers
D.
add-route is disabled in the tunnel IPSec phase 1 configuration.
Suggested answer: B, D

Explanation:

Option B is correct because the routing table shows that the tunnel interfaces have a netmask of 255.255.255.255, which indicates that net-device is enabled in the phase 1 configuration.This option allows the FortiGate to use the tunnel interface as a next-hop for routing, without adding a route to the phase 2 destination1.

Option D is correct because the routing table does not show any routes to the phase 2 destination networks, which indicates that add-route is disabled in the phase 1 configuration.This option controls whether the FortiGate adds a static route to the phase 2 destination network using the tunnel interface as the gateway2.

Option A is incorrect because IPSec tunnel aggregation is a feature that allows multiple phase 2 selectors to share a single phase 1 tunnel, reducing the number of tunnels and improving performance3. This feature is not related to the routing table or the phase 1 configuration.

Option C is incorrect because OSPF is a dynamic routing protocol that can run over IPSec tunnels, but it requires additional configuration on the FortiGate and the peer device4. This option is not related to the routing table or the phase 1 configuration.Reference: =

1: Technical Tip: 'set net-device' new route-based IPsec logic2

2: Adding a static route5

3: IPSec VPN concepts6

4: Dynamic routing over IPsec VPN7

asked 18/09/2024
Justin Schowalter
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first