NSE4 · Question #292
A network administrator needs to implement dynamic route redundancy between a FortiGate unit located in a remote office and a FortiGate unit located in the central office. The remote office accesses…
The correct answer is A. Use two or more route-based IPSec VPN tunnels and enable OSPF on the IPSec virtual. To implement dynamic route redundancy over multiple IPSec VPN tunnels between FortiGate units, using route-based VPNs with OSPF is the most effective method.
Question
A network administrator needs to implement dynamic route redundancy between a FortiGate unit located in a remote office and a FortiGate unit located in the central office. The remote office accesses central resources using IPSec VPN tunnels through two different Internet providers. What is the best method for allowing the remote office access to the resources through the FortiGate unit used at the central office?
Options
- AUse two or more route-based IPSec VPN tunnels and enable OSPF on the IPSec virtual
- BUse two or more policy-based IPSec VPN tunnels and enable OSPF on the IPSec virtual
- CUse route-based VPNs on the central office FortiGate unit to advertise routes with a dynamic
- DDynamic routing protocols cannot be used over IPSec VPN tunnels.
How the community answered
(19 responses)- A79% (15)
- B11% (2)
- C5% (1)
- D5% (1)
Why each option
To implement dynamic route redundancy over multiple IPSec VPN tunnels between FortiGate units, using route-based VPNs with OSPF is the most effective method.
Route-based IPSec VPN tunnels create virtual interfaces that dynamic routing protocols like OSPF can bind to. This allows FortiGate units to dynamically exchange routes and achieve automatic failover and load balancing across multiple VPN tunnels, providing robust redundancy.
Policy-based VPNs do not create virtual interfaces, making it impossible to enable dynamic routing protocols like OSPF directly over them for route advertisement and redundancy.
While route-based VPNs are correct, simply advertising routes with a dynamic metric using a static setup lacks the full automation and dynamic failover capabilities provided by OSPF.
Dynamic routing protocols such as OSPF and BGP are fully supported and commonly used over route-based IPSec VPN tunnels on FortiGate devices to enhance routing flexibility and redundancy.
Concept tested: IPSec VPN route redundancy with OSPF
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469440/ipsec-with-dynamic-routing
Topics
Community Discussion
No community discussion yet for this question.