nerdexam
Fortinet

FCSS_SDW_AR-7.4 · Question #3

Refer to the exhibit. The administrator configured the IPsec tunnel VPN1 on a FortiGate device with the parameters shown in exhibit. Based on the configuration, which three conclusions can you draw…

The correct answer is C. The administrator must manually assign the tunnel interface IP address on the hub side D. The remote end must support IKEv2. E. This configuration allows user-defined overlay IP addresses. The administrator must manually assign the tunnel interface IP address on the hub side The setting "set exchange-interface-ip enable" means the tunnel interface IP address is exchanged, but the hub side IP must be set manually. The remote end must support IKEv2 The command "set…

SD-WAN Integration

Question

Refer to the exhibit. The administrator configured the IPsec tunnel VPN1 on a FortiGate device with the parameters shown in exhibit. Based on the configuration, which three conclusions can you draw about the characteristics and requirements of the VPN tunnel? (Choose three.)

Exhibit

FCSS_SDW_AR-7.4 question #3 exhibit

Options

  • AThe tunnel interface IP address on the spoke side is provided by the hub.
  • BThe remote end can be a third-party IPsec device.
  • CThe administrator must manually assign the tunnel interface IP address on the hub side
  • DThe remote end must support IKEv2.
  • EThis configuration allows user-defined overlay IP addresses.

How the community answered

(47 responses)
  • A
    17% (8)
  • B
    9% (4)
  • C
    74% (35)

Explanation

The administrator must manually assign the tunnel interface IP address on the hub side The setting "set exchange-interface-ip enable" means the tunnel interface IP address is exchanged, but the hub side IP must be set manually. The remote end must support IKEv2 The command "set ike-version 2" explicitly configures IKE version 2 for this tunnel, so the remote device must support IKEv2. This configuration allows user-defined overlay IP addresses The tunnel interface enables user control over IP addressing for the overlay network, allowing custom IP assignments.

Topics

#IPsec tunnel#IKEv2#hub-spoke#tunnel interface IP

Community Discussion

No community discussion yet for this question.

Full FCSS_SDW_AR-7.4 Practice