NSE4 · Question #38
Review the static route configuration for IPsec shown in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)
The correct answer is A. Interface remote is an IPsec interface. B. A gateway address is not required because the interface is a point-to-point connection. When configuring a static route for IPsec on a FortiGate, if the outgoing interface is an IPsec tunnel interface, a gateway address is not required because the tunnel itself represents a point-to-point connection.
Question
Review the static route configuration for IPsec shown in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)
Exhibit
Options
- AInterface remote is an IPsec interface.
- BA gateway address is not required because the interface is a point-to-point connection.
- CA gateway address is not required because the default route is used.
- DInterface remote is a zone.
How the community answered
(46 responses)- A91% (42)
- C2% (1)
- D7% (3)
Why each option
When configuring a static route for IPsec on a FortiGate, if the outgoing interface is an IPsec tunnel interface, a gateway address is not required because the tunnel itself represents a point-to-point connection.
In FortiGate static route configuration, specifying a tunnel name like 'remote' (as implied by the exhibit) in the 'Device' field indicates that the traffic will be sent over an IPsec VPN tunnel, meaning 'remote' is an IPsec interface.
When the outgoing interface for a static route is an IPsec tunnel interface, which is a point-to-point logical connection, the gateway address is typically omitted as the traffic is encapsulated and forwarded directly through the tunnel.
The absence of a gateway address on a specific route does not imply that the default route is used; it indicates the specified interface acts as the direct next hop for that route.
While FortiGate supports zones, an IPsec interface is a distinct type of virtual interface representing a VPN tunnel, not a zone itself, although an IPsec interface can be part of a zone.
Concept tested: FortiGate IPsec static route configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/86958/static-route
Topics
Community Discussion
No community discussion yet for this question.
