ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 37 - NSE7_EFW-7.2 discussion

Report
Export

Exhibit.

Refer to the exhibit, which contains a partial VPN configuration.

What can you conclude from this configuration1?

A.
FortiGate creates separate virtual interfaces for each dial up client.
Answers
A.
FortiGate creates separate virtual interfaces for each dial up client.
B.
The VPN should use the dynamic routing protocol to exchange routing information Through the tunnels.
Answers
B.
The VPN should use the dynamic routing protocol to exchange routing information Through the tunnels.
C.
Dead peer detection s disabled.
Answers
C.
Dead peer detection s disabled.
D.
The routing table shows a single IPSec virtual interface.
Answers
D.
The routing table shows a single IPSec virtual interface.
Suggested answer: C

Explanation:

The configuration line ''set dpd on-idle'' indicates that dead peer detection (DPD) is set to trigger only when the tunnel is idle, not actively disabled1.Reference:FortiGate IPSec VPN User Guide - Fortinet Document Library

From the given VPN configuration, dead peer detection (DPD) is set to 'on-idle', indicating that DPD is enabled and will be used to detect if the other end of the VPN tunnel is still alive when no traffic is detected. Hence, option C is incorrect. The configuration shows the tunnel set to type 'dynamic', which does not create separate virtual interfaces for each dial-up client (A), and it is not specified that dynamic routing will be used (B). Since this is a phase 1 configuration snippet, the routing table aspect (D) cannot be concluded from this alone.

asked 18/09/2024
Maria Lilian Tongson
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first