Fortinet
NSE4_FGT_AD-7.6 · Question #71
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tunnel when both…
The correct answer is B. Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel. C. Enable Dead Peer Detection. You've hit your limit · resets 5am (America/New_York)
VPN
Question
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. All traffic must be routed through the primary tunnel when both tunnels are up. The secondary tunnel must be used only if the primary tunnel goes down. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover. Which two key configuration changes must the administrator make on FortiGate to meet the requirements? (Choose two.)
Options
- AIn the phasel-interface, enable npu-offload to detect a dead tunnel.
- BConfigure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
- CEnable Dead Peer Detection.
- DUse the VPN wizard to create an IPsec template for a redundant IPsec VPN tunnel.
How the community answered
(45 responses)- A16% (7)
- B78% (35)
- D7% (3)
Explanation
You've hit your limit · resets 5am (America/New_York)
Topics
#IPsec VPN#redundant tunnels#dead peer detection#route distance
Community Discussion
No community discussion yet for this question.