FCSS_EFW_AD-7.4 · Question #43
Refer to the exhibit, which shows a partial troubleshooting command output. An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the…
The correct answer is B. The two IPsec SAs, inbound and outbound, are copied to the NPU. The diagnose vpn tunnel list name Hub2Spoke1 command output provides key information about the offloading status of an IPsec VPN tunnel to the Network Processing Unit (NPU). This flag indicates that both inbound and outbound IPsec Security Associations (SAs) have been offloaded…
Question
Refer to the exhibit, which shows a partial troubleshooting command output. An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to the output shown in the exhibit. What can the administrator conclude?
Exhibit
Options
- AIPsec SAs cannot be offloaded.
- BThe two IPsec SAs, inbound and outbound, are copied to the NPU.
- COnly the outbound IPsec SA is copied to the NPU.
- DOnly the inbound IPsec SA is copied to the NPU.
How the community answered
(41 responses)- A2% (1)
- B80% (33)
- C12% (5)
- D5% (2)
Explanation
The diagnose vpn tunnel list name Hub2Spoke1 command output provides key information about the offloading status of an IPsec VPN tunnel to the Network Processing Unit (NPU). This flag indicates that both inbound and outbound IPsec Security Associations (SAs) have been offloaded to the NPU, meaning the VPN traffic is processed in hardware instead of the CPU. npu_rgwy=10.10.2.2 and npu_lgwy=10.10.1.1: These IPs represent the remote gateway (rgwy) and local gateway (lgwy), confirming that the tunnel is successfully offloaded. This value means the session selector for the NPU offloaded SA is active. Since both inbound and outbound SAs are offloaded, the administrator can conclude that the FortiGate NPU is handling IPsec encryption and decryption efficiently, reducing CPU load and improving VPN performance.
Topics
Community Discussion
No community discussion yet for this question.
