nerdexam
Fortinet

FCSS_EFW_AD-7.6 · Question #65

Refer to the exhibit, which shows an ADVPN network. An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2. What must the administrator configure in the…

The correct answer is B. set auto-discovery-forwarder enable. In a Hub2Hub ADVPN topology connecting two separate overlay networks, the hub acts as an intermediary that must forward auto-discovery shortcut messages originating from one overlay's spokes to the other overlay's spokes. Setting auto-discovery-forwarder enable on the Hub2Hub…

VPN

Question

Refer to the exhibit, which shows an ADVPN network. An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2. What must the administrator configure in the phase 1 VPN IPSEC configuration of the Hub2Hub tunnels?

Exhibit

FCSS_EFW_AD-7.6 question #65 exhibit

Options

  • Aset auto-discovery-sender enable
  • Bset auto-discovery-forwarder enable
  • Cset add-route enable
  • Dset auto-discovery-receiver enable

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    80% (24)
  • C
    13% (4)
  • D
    3% (1)

Explanation

In a Hub2Hub ADVPN topology connecting two separate overlay networks, the hub acts as an intermediary that must forward auto-discovery shortcut messages originating from one overlay's spokes to the other overlay's spokes. Setting auto-discovery-forwarder enable on the Hub2Hub tunnel phase 1 configuration enables this relay behavior, allowing spokes across different overlays to negotiate direct IPsec shortcuts without Hub2Hub becoming a permanent data-plane bottleneck.

Why the distractors fail:

  • A (sender) is for hub interfaces facing their own spokes - it initiates shortcut suggestions, not forwards them between overlays.
  • C (add-route) controls whether a route is injected for a shortcut tunnel after it forms; it has no bearing on the discovery signaling path between hubs.
  • D (receiver) is configured on spoke interfaces so they can accept shortcut offers from their local hub - it's a spoke-side setting, not a hub-to-hub one.

Memory tip: Think of the Hub2Hub link as a postal relay office - it doesn't originate (sender) or terminate (receiver) the shortcut messages; it just forwards them along. Forwarder = the middle node in the chain.

Topics

#ADVPN#Hub2Hub#auto-discovery-forwarder#overlay routing

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.6 Practice