NSE4 · Question #306
View the exhibit. Which of the following statements are correct? (Choose two.)
The correct answer is A. This is a redundant IPsec setup. B. The TunnelB route is the primary one for searching the remote site. The TunnelA route is used. The exhibit shows two static routes to the same destination network via different IPsec tunnels with varying priorities, indicating a redundant setup.
Question
View the exhibit. Which of the following statements are correct? (Choose two.)
Exhibits
Options
- AThis is a redundant IPsec setup.
- BThe TunnelB route is the primary one for searching the remote site. The TunnelA route is used
- CThis setup requires at least two firewall policies with action set to IPsec.
- DDead peer detection must be disabled to support this type of IPsec setup.
How the community answered
(17 responses)- A94% (16)
- D6% (1)
Why each option
The exhibit shows two static routes to the same destination network via different IPsec tunnels with varying priorities, indicating a redundant setup.
Configuring two static routes for the same destination network through different interfaces (IPsec tunnels) with distinct priorities establishes a redundant IPsec setup, allowing traffic to fail over if the primary tunnel becomes unavailable.
Assuming a routing context where a higher priority value indicates a preferred route (contrary to standard FortiGate priority where lower is preferred), the TunnelB route (priority 10) would be selected as primary over TunnelA (priority 0) for reaching the remote site.
This setup typically requires one firewall policy with action set to IPsec that encompasses both tunnels, often managed by SD-WAN rules, rather than separate policies for each tunnel.
Dead Peer Detection (DPD) is a critical feature that should generally be enabled in redundant IPsec setups to rapidly detect tunnel failures and facilitate quick failover to the backup tunnel.
Concept tested: FortiGate redundant static routes for IPsec VPN
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/209121/redundant-static-routes
Topics
Community Discussion
No community discussion yet for this question.

