nerdexam
Fortinet

FCSS_EFW_AD-7.4 · Question #43

Refer to the exhibit, which shows a partial troubleshooting command output. An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the…

The correct answer is B. The two IPsec SAs, inbound and outbound, are copied to the NPU. The diagnose vpn tunnel list name Hub2Spoke1 command output provides key information about the offloading status of an IPsec VPN tunnel to the Network Processing Unit (NPU). This flag indicates that both inbound and outbound IPsec Security Associations (SAs) have been offloaded…

Hardware Acceleration

Question

Refer to the exhibit, which shows a partial troubleshooting command output. An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the exhibit. What can the administrator conclude?

Exhibit

FCSS_EFW_AD-7.4 question #43 exhibit

Options

  • AIPsec SAs cannot be offloaded.
  • BThe two IPsec SAs, inbound and outbound, are copied to the NPU.
  • COnly the outbound IPsec SA is copied to the NPU.
  • DOnly the inbound IPsec SA is copied to the NPU.

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    80% (33)
  • C
    12% (5)
  • D
    5% (2)

Explanation

The diagnose vpn tunnel list name Hub2Spoke1 command output provides key information about the offloading status of an IPsec VPN tunnel to the Network Processing Unit (NPU). This flag indicates that both inbound and outbound IPsec Security Associations (SAs) have been offloaded to the NPU, meaning the VPN traffic is processed in hardware instead of the CPU. npu_rgwy=10.10.2.2 and npu_lgwy=10.10.1.1: These IPs represent the remote gateway (rgwy) and local gateway (lgwy), confirming that the tunnel is successfully offloaded. This value means the session selector for the NPU offloaded SA is active. Since both inbound and outbound SAs are offloaded, the administrator can conclude that the FortiGate NPU is handling IPsec encryption and decryption efficiently, reducing CPU load and improving VPN performance.

Topics

#IPsec SA#NPU offloading#NP acceleration#inbound outbound SA

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.4 Practice