nerdexam
Fortinet

FCSS_SASE_AD-23 · Question #7

FCSS_SASE_AD-23 Question #7: Real Exam Question with Answer & Explanation

Sign in or unlock FCSS_SASE_AD-23 to reveal the answer and full explanation for question #7. The question stem and answer options stay visible for context.

Question

Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish. Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?

Exhibits

FCSS_SASE_AD-23 question #7 exhibit 1
FCSS_SASE_AD-23 question #7 exhibit 2
FCSS_SASE_AD-23 question #7 exhibit 3
FCSS_SASE_AD-23 question #7 exhibit 4
FCSS_SASE_AD-23 question #7 exhibit 5

Options

  • ANAT needs to be enabled in the Spoke-to-Hub firewall policy.
  • BThe BGP router ID needs to match on the hub and FortiSASE.
  • CFortiSASE spoke devices do not support mode config.
  • DThe hub needs IKEv2 enabled in the IPsec phase 1 settings.

Unlock FCSS_SASE_AD-23 to see the answer

You've previewed enough free FCSS_SASE_AD-23 questions. Unlock FCSS_SASE_AD-23 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full FCSS_SASE_AD-23 Practice