ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 29 - NSE8_812 discussion

Report
Export

A customer is planning on moving their secondary data center to a cloud-based laaS. They want to place all the Oracle-based systems Oracle Cloud, while the other systems will be on Microsoft Azure with ExpressRoute service to their main data center.

They have about 200 branches with two internet services as their only WAN connections. As a security consultant you are asked to design an architecture using Fortinet products with security, redundancy and performance as a priority.

Which two design options are true based on these requirements? (Choose two.)

A.
Systems running on Azure will need to go through the main data center to access the services on Oracle Cloud.
Answers
A.
Systems running on Azure will need to go through the main data center to access the services on Oracle Cloud.
B.
Use FortiGate VM for IPSEC over ExpressRoute, as traffic is not encrypted by Azure.
Answers
B.
Use FortiGate VM for IPSEC over ExpressRoute, as traffic is not encrypted by Azure.
C.
Branch FortiGate devices must be configured as VPN clients for the branches' internal network to be able to access Oracle services without using public IPs.
Answers
C.
Branch FortiGate devices must be configured as VPN clients for the branches' internal network to be able to access Oracle services without using public IPs.
D.
Two ExpressRoute services to the main data center are required to implement SD-WAN between a FortiGate VM in Azure and a FortiGate device at the data center edge
Answers
D.
Two ExpressRoute services to the main data center are required to implement SD-WAN between a FortiGate VM in Azure and a FortiGate device at the data center edge
Suggested answer: B, D

Explanation:

To secure the traffic between Azure and the main data center, a FortiGate VM can be deployed in

Azure and configured to use IPSEC over ExpressRoute, as traffic is not encrypted by Azure by default.

This also allows the use of Fortinet security features such as antivirus, IPS, web filtering, and application control. To implement SD-WAN between Azure and the main data center, two ExpressRoute services are required to provide redundant paths and load balancing. A FortiGate device at the data center edge can be configured to use SD-WAN rules to select the best path based on performance, availability, and cost. Reference:

https://docs.fortinet.com/document/fortigate/6.4.0/cookbook/103440/ipsec-vpn-betweenfortigate-and-azure https://docs.fortinet.com/document/fortigate/6.4.0/cookbook/103441/sd-wanbetween-fortigate-and-azure

asked 18/09/2024
Ali Alaqoul
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first