ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 9 - NSE7_PBC-7.2 discussion

Report
Export

Refer to Exhibit:

The exhibit shows the Connect Peers settings on Amazon Web Services (AWS) transit gateway attachments With two FortiGate VMS in a security VPC.

Which two statements are correct? (Choose two.)

A.
The peer GRE address is the FortiGate external interface IP address.
Answers
A.
The peer GRE address is the FortiGate external interface IP address.
B.
The Transit Gateway GRE address is auto-generated
Answers
B.
The Transit Gateway GRE address is auto-generated
C.
The BGP inside CIDR blocks can be any CIDR block with /29
Answers
C.
The BGP inside CIDR blocks can be any CIDR block with /29
D.
The Peer GRE address is the FortiGate internal interface IP address
Answers
D.
The Peer GRE address is the FortiGate internal interface IP address
Suggested answer: A, B

Explanation:

A) The peer GRE address is the FortiGate external interface IP address.This is the IP address of the FortiGate interface that is connected to the transit gateway attachment subnet1.This IP address is used to establish the GRE tunnel between the FortiGate and the transit gateway2. B) The Transit Gateway GRE address is auto-generated.This is the IP address of the transit gateway that is used to establish the GRE tunnel with the FortiGate2.This IP address is automatically assigned by AWS from the Transit Gateway CIDR range that you specify when you create the Connect attachment3.

The other options are incorrect because:

The BGP inside CIDR blocks cannot be any CIDR block with /29.They must be a /29 CIDR block from the 169.254.0.0/16 range for IPv4, or a /125 CIDR block from the fd00::/8 range for IPv64.These are the inside IP addresses that are used for BGP peering over the GRE tunnel4.

The Peer GRE address is not the FortiGate internal interface IP address.The internal interface IP address is used to route traffic from the FortiGate to the VPC subnet where the third-party appliance (such as SD-WAN) is located1.The Peer GRE address is used to route traffic from the FortiGate to the transit gateway over the GRE tunnel2.

asked 18/09/2024
Zarate, Wilfredo
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first