nerdexam
Fortinet

FCSS_SDW_AR-7.4 · Question #11

You are tasked with configuring ADVPN 2.0 on an SD-WAN topology already configured for ADVPN. What should you do to implement ADVPN 2.0 in this scenario?

The correct answer is B. Update the SD-WAN configuration on the branches. ADVPN-2.0 is implemented by changing how SD-WAN selects/creates dynamic VPNs between sites (it uses the SD-WAN/ADVPN settings so spokes can form direct child tunnels). If your topology already has ADVPN (legacy) IPsec tunnels in place, you normally do not need to rip…

SD-WAN Integration

Question

You are tasked with configuring ADVPN 2.0 on an SD-WAN topology already configured for ADVPN. What should you do to implement ADVPN 2.0 in this scenario?

Options

  • AUpdate the IPsec tunnel configurations on the hub.
  • BUpdate the SD-WAN configuration on the branches.
  • CUpdate the IPsec tunnel configuration on the branches.
  • DDelete the existing ADVPN configuration and configure ADVPN 2.0.

How the community answered

(30 responses)
  • A
    17% (5)
  • B
    73% (22)
  • C
    7% (2)
  • D
    3% (1)

Explanation

ADVPN-2.0 is implemented by changing how SD-WAN selects/creates dynamic VPNs between sites (it uses the SD-WAN/ADVPN settings so spokes can form direct child tunnels). If your topology already has ADVPN (legacy) IPsec tunnels in place, you normally do not need to rip- and-replace existing IPsec tunnel definitions on hub or spokes - instead you enable and adjust the ADVPN-2.0-related settings in the SD-WAN configuration on the branch devices so they will negotiate and use the ADVPN-2.0 behavior.

Topics

#ADVPN 2.0#SD-WAN branch configuration#ADVPN upgrade#shortcut tunnels

Community Discussion

No community discussion yet for this question.

Full FCSS_SDW_AR-7.4 Practice