nerdexam
Fortinet

FCSS_EFW_AD-7.4 · Question #13

Refer to the exhibit, which shows the ADVPN IPsec interface representing the VPN IPsec phase 1 from Hub A to Spoke 1 and Spoke 2, and from Hub to Spoke 3 and Spoke 4. An administrator must configure…

The correct answer is C. set auto-discovery-crossover enable and set enforce-multihop enable. When configuring ADVPN (Auto-Discovery VPN) to connect overlay networks across different hubs using IBGP and EBGP, special configurations are required to allow spokes from different overlay networks to dynamically establish tunnels. set auto-discovery-crossover enable This…

VPN

Question

Refer to the exhibit, which shows the ADVPN IPsec interface representing the VPN IPsec phase 1 from Hub A to Spoke 1 and Spoke 2, and from Hub to Spoke 3 and Spoke 4. An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2. What must the administrator configure in the phase 1 VPN IPsec configuration of the ADVPN tunnels?

Exhibit

FCSS_EFW_AD-7.4 question #13 exhibit

Options

  • Aset auto-discovery-sender enable and set network-id x
  • Bset auto-discovery-forwarder enable and set remote-as x
  • Cset auto-discovery-crossover enable and set enforce-multihop enable
  • Dset auto-discovery-receiver enable and set npu-offload enable

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    83% (24)
  • D
    3% (1)

Explanation

When configuring ADVPN (Auto-Discovery VPN) to connect overlay networks across different hubs using IBGP and EBGP, special configurations are required to allow spokes from different overlay networks to dynamically establish tunnels. set auto-discovery-crossover enable This allows cross-hub tunnel discovery in an ADVPN deployment where multiple hubs are used. Since Hub A and Hub B belong to different overlays, enabling crossover discovery ensures that spokes from one overlay can dynamically create direct tunnels to spokes in the other overlay set enforce-multihop enable This setting ensures that BGP peers using loopback interfaces can establish connectivity even if they are not directly connected. Multihop BGP sessions are required when using loopback addresses as BGP peer sources because the connection might need to traverse multiple routers before reaching the BGP neighbor. This is especially useful in ADVPN deployments with multiple hubs, where routes might need to cross from one hub to another.

Topics

#ADVPN#IPsec phase 1#IBGP/EBGP crossover#auto-discovery-crossover

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.4 Practice