nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #72

An administrator has configured a dialup IPsec VPN on FortiGate with add-route enabled. However, the static route is not showing in the routing table. Which two statements about this scenario are…

The correct answer is C. The administrator must ensure phase 2 is successfully established. D. The administrator must define the remote network correctly in the phase 2 selectors. The administrator must ensure phase 2 is successfully established → The static route for the dialup VPN is only added after Phase 2 negotiation completes successfully. The administrator must define the remote network correctly in the phase 2 selectors → The add- route feature…

Submitted by jakub_pl· Apr 18, 2026VPN

Question

An administrator has configured a dialup IPsec VPN on FortiGate with add-route enabled. However, the static route is not showing in the routing table. Which two statements about this scenario are correct? (Choose two.)

Options

  • AThe administrator must enable a dynamic routing protocol on the dialup interface.
  • BThe administrator must use a policy route instead of a static route for add-route to work properly.
  • CThe administrator must ensure phase 2 is successfully established.
  • DThe administrator must define the remote network correctly in the phase 2 selectors.

How the community answered

(20 responses)
  • A
    15% (3)
  • B
    5% (1)
  • C
    80% (16)

Explanation

The administrator must ensure phase 2 is successfully established → The static route for the dialup VPN is only added after Phase 2 negotiation completes successfully. The administrator must define the remote network correctly in the phase 2 selectors → The add- route feature installs a route based on the Phase 2 selectors; if they are incorrect, no route will appear in the routing table.

Topics

#IPsec VPN#FortiGate Routing#Phase 2 Selectors#VPN Troubleshooting

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice