nerdexam
Fortinet

FCSS_EFW_AD-7.4 · Question #29

Refer to the exhibit, which contains a partial command output. The administrator has configured BGP on FortiGate. The status of this new BGP configuration is shown in the exhibit. What configuration…

The correct answer is D. Enable ebgp-enforce-multihop. From the BGP neighbor status output, the key issue is that BGP is stuck in the "Idle" state, meaning the FortiGate is unable to establish a BGP session with its peer 100.65.4.1 (Remote AS The output also shows: "Not directly connected EBGP" This means the BGP peer is not on the…

Routing

Question

Refer to the exhibit, which contains a partial command output. The administrator has configured BGP on FortiGate. The status of this new BGP configuration is shown in the exhibit. What configuration must the administrator consider next?

Exhibit

FCSS_EFW_AD-7.4 question #29 exhibit

Options

  • AConfigure a static route to 100.65.4.1.
  • BConfigure the local AS to 65300.
  • CContact the remote peer administrator to enable BGP
  • DEnable ebgp-enforce-multihop.

How the community answered

(55 responses)
  • A
    4% (2)
  • B
    13% (7)
  • C
    5% (3)
  • D
    78% (43)

Explanation

From the BGP neighbor status output, the key issue is that BGP is stuck in the "Idle" state, meaning the FortiGate is unable to establish a BGP session with its peer 100.65.4.1 (Remote AS The output also shows: "Not directly connected EBGP" This means the BGP peer is not on the same subnet, requiring "Update source is Loopback" Since a loopback interface is used, FortiGate must be configured to allow BGP neighbors over multiple hops. To resolve this issue, the administrator must enable ebgp-enforce-multihop, which allows BGP sessions to be established even when the neighbors are not directly connected.

Topics

#BGP#ebgp-enforce-multihop#BGP neighbor troubleshooting#multihop EBGP

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.4 Practice