nerdexam
Fortinet

NSE4_FGT-6.4 · Question #35

A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. - All traffic must be routed through the primary tunnel when both…

The correct answer is A. Enable Dead Peer Detection. B. Configure a lower distance on the static route for the primary tunnel, and a higher distance on the. See the full explanation below for the reasoning.

Question

A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes.

  • All traffic must be routed through the primary tunnel when both tunnels are up
  • The secondary tunnel must be used only if the primary tunnel goes down
  • In addition, FortiGate should be able to detect a dead tunnel to speed up tunnelfailover

Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two,)

Options

  • AEnable Dead Peer Detection.
  • BConfigure a lower distance on the static route for the primary tunnel, and a higher distance on the
  • CEnable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.
  • DConfigure a higher distance on the static route for the primary tunnel, and a lower distance on the

How the community answered

(21 responses)
  • A
    86% (18)
  • C
    5% (1)
  • D
    10% (2)

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT-6.4 Practice