ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 50 - NSE8_812 discussion

Report
Export

Refer to the exhibit.

To facilitate a large-scale deployment of SD-WAN/ADVPN with FortiGate devices, you are tasked with configuring the FortiGate devices to support injecting of IKE routes on the ADVPN shortcut tunnels.

Which three commands must be added or changed to the FortiGate spoke config vpn ipsec phaseiinterface options referenced in the exhibit for the VPN interface to enable this capability? (Choose three.)

A.
set net-device disable
Answers
A.
set net-device disable
B.
set mode-cfg enable
Answers
B.
set mode-cfg enable
C.
set ike-version 1
Answers
C.
set ike-version 1
D.
set add-route enable
Answers
D.
set add-route enable
E.
set mode-cfg-allow-client-selector enable
Answers
E.
set mode-cfg-allow-client-selector enable
Suggested answer: A, D, E

Explanation:

A is correct because net-device disable prevents the VPN interface from being added to the routing table as a connected route. This allows IKE routes to be injected instead. D is correct because addroute enable enables IKE route injection on the VPN interface. E is correct because mode-cfg-allowclient-selector enable allows the VPN interface to accept IKE routes from any peer that matches the phase 1 configuration. Reference:

https://docs.fortinet.com/document/fortigate/7.0.1/administration-guide/490352/advpn

https://docs.fortinet.com/document/fortigate/7.0.1/administration-guide/490352/advpnconfiguration

asked 18/09/2024
Bruce Baynes
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first