FCSS_EFW_AD-7.6 · Question #64
Refer to the exhibit, which shows a partial routing table. What two conclusions can you draw from the FortiGate output shown in the exhibit? (Choose two.)
The correct answer is C. FortiGate is not using the destination subnets of the quick mode selectors to populate the D. net-device is disabled in the tunnel IPSec phase 1 configuration. When net-device is disabled (D), FortiGate does not create individual virtual interfaces per VPN client - instead, all traffic uses the shared tunnel interface. Because net-device is disabled, FortiGate also does not automatically inject routes derived from the Phase 2 quick…
Question
Refer to the exhibit, which shows a partial routing table. What two conclusions can you draw from the FortiGate output shown in the exhibit? (Choose two.)
Exhibit
Options
- AFortiGate creates separate virtual interfaces for each VPN client.
- Badd-route is enabled in the tunnel IPSec phase 1 configuration.
- CFortiGate is not using the destination subnets of the quick mode selectors to populate the
- Dnet-device is disabled in the tunnel IPSec phase 1 configuration.
How the community answered
(22 responses)- A27% (6)
- B14% (3)
- C59% (13)
Explanation
When net-device is disabled (D), FortiGate does not create individual virtual interfaces per VPN client - instead, all traffic uses the shared tunnel interface. Because net-device is disabled, FortiGate also does not automatically inject routes derived from the Phase 2 quick mode selector subnets into the routing table, which is exactly what option C describes. Together, C and D paint a consistent picture: a tunnel-mode IPSec setup where route injection from selectors is suppressed.
Why A is wrong: Separate virtual interfaces per client are a feature of net-device being enabled - the opposite of what the routing table output implies.
Why B is wrong: If add-route were enabled, FortiGate would populate the routing table with the destination subnets from the quick mode selectors - directly contradicting C.
Memory tip: Think of it as two "off switches" working together - net-device OFF → no per-client virtual interfaces (kills A); add-route OFF → no auto-routes from Phase 2 selectors (kills B, confirms C). If you see a sparse routing table with no selector-derived subnets, both features are likely disabled.
Topics
Community Discussion
No community discussion yet for this question.
