nerdexam
Fortinet

NSE6_SDW_AD-7.6 · Question #3

Refer to the exhibit. The administrator configured the IPsec tunnel VPN1 on a FortiGate device with the parameters shown in exhibit. Based on the configuration, which three conclusions can you draw…

The correct answer is C. The administrator must manually assign the tunnel interface IP address on the hub side D. The remote end must support IKEv2. E. This configuration allows user-defined overlay IP addresses. The administrator must manually assign the tunnel interface IP address on the hub side The setting "set exchange-interface-ip enable" means the tunnel interface IP address is exchanged, but the hub side IP must be set manually. The remote end must support IKEv2 The command "set…

Initial Deployment and Configuration

Question

Refer to the exhibit. The administrator configured the IPsec tunnel VPN1 on a FortiGate device with the parameters shown in exhibit. Based on the configuration, which three conclusions can you draw about the characteristics and requirements of the VPN tunnel? (Choose three.)

Exhibit

NSE6_SDW_AD-7.6 question #3 exhibit

Options

  • AThe tunnel interface IP address on the spoke side is provided by the hub.
  • BThe remote end can be a third-party IPsec device.
  • CThe administrator must manually assign the tunnel interface IP address on the hub side
  • DThe remote end must support IKEv2.
  • EThis configuration allows user-defined overlay IP addresses.

How the community answered

(35 responses)
  • A
    11% (4)
  • B
    20% (7)
  • C
    69% (24)

Explanation

The administrator must manually assign the tunnel interface IP address on the hub side The setting "set exchange-interface-ip enable" means the tunnel interface IP address is exchanged, but the hub side IP must be set manually. The remote end must support IKEv2 The command "set ike-version 2" explicitly configures IKE version 2 for this tunnel, so the remote device must support IKEv2. This configuration allows user-defined overlay IP addresses The tunnel interface enables user control over IP addressing for the overlay network, allowing custom IP assignments.

Topics

#IPsec VPN#IKEv2#hub-and-spoke#overlay IP assignment

Community Discussion

No community discussion yet for this question.

Full NSE6_SDW_AD-7.6 Practice