nerdexam
Fortinet

FCSS_SASE_AD-24 · Question #7

Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish. Based on the provided configuration, what…

The correct answer is D. The hub needs IKEv2 enabled in the IPsec phase 1 settings. See the full explanation below for the reasoning.

Question

Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish. Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?

Exhibits

FCSS_SASE_AD-24 question #7 exhibit 1
FCSS_SASE_AD-24 question #7 exhibit 2
FCSS_SASE_AD-24 question #7 exhibit 3
FCSS_SASE_AD-24 question #7 exhibit 4
FCSS_SASE_AD-24 question #7 exhibit 5

Options

  • ANAT needs to be enabled in the Spoke-to-Hub firewall policy.
  • BThe BGP router ID needs to match on the hub and FortiSASE.
  • CFortiSASE spoke devices do not support mode config.
  • DThe hub needs IKEv2 enabled in the IPsec phase 1 settings.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    17% (5)
  • D
    70% (21)

Community Discussion

No community discussion yet for this question.

Full FCSS_SASE_AD-24 Practice