ExamGecko
Question list
Search
Search

Question 20 - NSE7_NST-7.2 discussion

Report
Export

Exhibit.

Refer to the exhibit, which contains the partial output of the get vpn ipsec tunnel details command. Based on the output, which two statements are correct? (Choose two.)

A.
Anti-replay is enabled.
Answers
A.
Anti-replay is enabled.
B.
The npu_flag for this tunnel is 03.
Answers
B.
The npu_flag for this tunnel is 03.
C.
The npu_flag for this tunnel is 02
Answers
C.
The npu_flag for this tunnel is 02
D.
Different SPI values are a result of auto-negotiation being disabled for phase 2 selectors.
Answers
D.
Different SPI values are a result of auto-negotiation being disabled for phase 2 selectors.
Suggested answer: A, C

Explanation:

Anti-replay Enabled:

The exhibit shows replay: enabled, which confirms that anti-replay is enabled for this IPsec tunnel. Anti-replay is a security feature that prevents replay attacks by ensuring that packets are not duplicated or reused.

NPU Acceleration:

The NPU acceleration: encryption (outbound) decryption (inbound) line indicates that Network Processing Unit (NPU) acceleration is used.

The npu_flag for this tunnel is 02. This indicates that encryption and decryption are handled by the NPU, improving the performance of the VPN tunnel.

Fortinet Community: Troubleshooting IPsec VPN Tunnels (Welcome to the Fortinet Community!) (Welcome to the Fortinet Community!).

Fortinet Documentation: Verifying IPsec VPN Tunnels (Fortinet Docs) (Fortinet Docs).

asked 18/09/2024
Kees den Dekker
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first