nerdexam
Fortinet

FCSS_SDW_AR-7.4 · Question #20

Refer to the exhibit. The administrator used the SD-WAN overlay template to prepare an IPsec tunnels configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the FortiManager…

The correct answer is B. It is a hub device. It can send ADVPN shortcut offers. The phase1-interface shows set type dynamic, set peertype any, and set mode-cfg enable with an address pool (ipv4-start-ip, ipv4-end-ip, ipv4-netmask). Those are dial-up server settings-i.e., a hub handing out virtual IPs to spokes. It also has set auto- discovery-sender…

SD-WAN Deployment Strategies

Question

Refer to the exhibit. The administrator used the SD-WAN overlay template to prepare an IPsec tunnels configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the FortiManager installation preview for one FortiGate device. Based on the exhibit, which statement best describes the configuration applied to the FortiGate device?

Exhibit

FCSS_SDW_AR-7.4 question #20 exhibit

Options

  • AIt is a spoke device that establishes dynamic IPsec tunnels to the hub. The local subnet range is
  • BIt is a hub device. It can send ADVPN shortcut offers.
  • CIt is a hub device. It will automatically discover the spoke devices and add them to the SD-WAN
  • DIt is a spoke device that establishes dynamic IPsec tunnels to the hub It can send ADVPN

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    74% (17)
  • C
    9% (2)
  • D
    13% (3)

Explanation

The phase1-interface shows set type dynamic, set peertype any, and set mode-cfg enable with an address pool (ipv4-start-ip, ipv4-end-ip, ipv4-netmask). Those are dial-up server settings-i.e., a hub handing out virtual IPs to spokes. It also has set auto- discovery-sender enable, allowing the hub to participate in ADVPN shortcut negotiation (sending offers).

Topics

#overlay template#hub device#ADVPN#IPsec tunnel

Community Discussion

No community discussion yet for this question.

Full FCSS_SDW_AR-7.4 Practice