nerdexam
Fortinet

FCSS_EFW_AD-7.6 · Question #64

Refer to the exhibit, which shows a partial routing table. What two conclusions can you draw from the FortiGate output shown in the exhibit? (Choose two.)

The correct answer is C. FortiGate is not using the destination subnets of the quick mode selectors to populate the D. net-device is disabled in the tunnel IPSec phase 1 configuration. When net-device is disabled (D), FortiGate does not create individual virtual interfaces per VPN client - instead, all traffic uses the shared tunnel interface. Because net-device is disabled, FortiGate also does not automatically inject routes derived from the Phase 2 quick…

VPN

Question

Refer to the exhibit, which shows a partial routing table. What two conclusions can you draw from the FortiGate output shown in the exhibit? (Choose two.)

Exhibit

FCSS_EFW_AD-7.6 question #64 exhibit

Options

  • AFortiGate creates separate virtual interfaces for each VPN client.
  • Badd-route is enabled in the tunnel IPSec phase 1 configuration.
  • CFortiGate is not using the destination subnets of the quick mode selectors to populate the
  • Dnet-device is disabled in the tunnel IPSec phase 1 configuration.

How the community answered

(22 responses)
  • A
    27% (6)
  • B
    14% (3)
  • C
    59% (13)

Explanation

When net-device is disabled (D), FortiGate does not create individual virtual interfaces per VPN client - instead, all traffic uses the shared tunnel interface. Because net-device is disabled, FortiGate also does not automatically inject routes derived from the Phase 2 quick mode selector subnets into the routing table, which is exactly what option C describes. Together, C and D paint a consistent picture: a tunnel-mode IPSec setup where route injection from selectors is suppressed.

Why A is wrong: Separate virtual interfaces per client are a feature of net-device being enabled - the opposite of what the routing table output implies.

Why B is wrong: If add-route were enabled, FortiGate would populate the routing table with the destination subnets from the quick mode selectors - directly contradicting C.

Memory tip: Think of it as two "off switches" working together - net-device OFF → no per-client virtual interfaces (kills A); add-route OFF → no auto-routes from Phase 2 selectors (kills B, confirms C). If you see a sparse routing table with no selector-derived subnets, both features are likely disabled.

Topics

#IPsec routing#net-device#add-route#quick mode selectors

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.6 Practice