ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 18 - NSE8_812 discussion

Report
Export

Refer to the exhibit.

A customer has deployed a FortiGate 300E with virtual domains (VDOMs) enabled in the multi-VDOM mode. There are three VDOMs: Root is for management and internet access, while VDOM 1 and VDOM 2 are used for segregating internal traffic. AccountVInk and SalesVInk are standard VDOM links in Ethernet mode.

Given the exhibit, which two statements below about VDOM behavior are correct? (Choose two.)

A.
You can apply OSPF routing on the VDOM link in either PPP or Ethernet mode
Answers
A.
You can apply OSPF routing on the VDOM link in either PPP or Ethernet mode
B.
Traffic on AccountVInk and SalesVInk will not be accelerated.
Answers
B.
Traffic on AccountVInk and SalesVInk will not be accelerated.
C.
The VDOM links are in Ethernet mode because they have IP addressed assigned on both sides.
Answers
C.
The VDOM links are in Ethernet mode because they have IP addressed assigned on both sides.
D.
Root VDOM is an Admin type VDOM, while VDOM 1 and VDOM 2 are Traffic type VDOMs.
Answers
D.
Root VDOM is an Admin type VDOM, while VDOM 1 and VDOM 2 are Traffic type VDOMs.
E.
OSPF routing can be configured between VDOM 1 and Root VDOM without any configuration changes to AccountVInk
Answers
E.
OSPF routing can be configured between VDOM 1 and Root VDOM without any configuration changes to AccountVInk
Suggested answer: B, D

Explanation:

The FortiGate configuration shown in the exhibit is using virtual domains (VDOMs) enabled in multi-VDOM mode. There are three VDOMs: Root is for management and internet access, while VDOM 1 and VDOM 2 are used for segregating internal traffic. AccountVInk and SalesVInk are standard VDOM links in Ethernet mode. One correct statement about VDOM behavior is that traffic on AccountVInk and SalesVInk will not be accelerated. This is because standard VDOM links do not support hardware acceleration features such as NP6 or CP9 offloading, which can improve performance and throughput for traffic between VDOMs. To enable hardware acceleration for inter-VDOM traffic, non-standard VDOM links such as NP6 or CP9 interfaces should be used instead of standard VDOM links. Another correct statement about VDOM behavior is that Root VDOM is an Admin type VDOM, while VDOM 1 and VDOM 2 are Traffic type VDOMs. This is because Admin type VDOMs are special VDOMs that can only be used for management purposes and cannot process any traffic other than management traffic (such as SSH, HTTPS, SNMP, etc.). Traffic type VDOMs are normal VDOMs that can process any kind of traffic (such as firewall policies, VPN tunnels, routing protocols, etc.). By default, Root VDOM is an Admin type VDOM that can manage other Traffic type VDOMs, unless it is converted to a Traffic type VDOM by using the set vdom-admin enable command. Reference:

https://docs.fortinet.com/document/fortigate/7.0.0/administration-guide/19662/virtual-domains

https://docs.fortinet.com/document/fortigate/7.0.0/hardware-acceleration-guide/19662/vdom-links

asked 18/09/2024
Matteo Zamori
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first