nerdexam
Fortinet

NSE7_EFW-7.2 · Question #46

Refer to the exhibit, which shows a partial touting table. What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

The correct answer is B. net-device is enabled in the tunnel IPSec phase 1 configuration D. add-route is disabled in the tunnel IPSec phase 1 configuration. Option B is correct because the routing table shows that the tunnel interfaces have a netmask of 255.255.255.255, which indicates that net-device is enabled in the phase 1 configuration. This option allows the FortiGate to use the tunnel interface as a next-hop for routing…

FortiGate VPN

Question

Refer to the exhibit, which shows a partial touting table. What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

Exhibit

NSE7_EFW-7.2 question #46 exhibit

Options

  • AIPSec Tunnel aggregation is configured
  • Bnet-device is enabled in the tunnel IPSec phase 1 configuration
  • COSPI is configured to run over IPSec.
  • Dadd-route is disabled in the tunnel IPSec phase 1 configuration.

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    82% (31)
  • C
    13% (5)

Explanation

Option B is correct because the routing table shows that the tunnel interfaces have a netmask of 255.255.255.255, which indicates that net-device is enabled in the phase 1 configuration. This option allows the FortiGate to use the tunnel interface as a next-hop for routing, without adding a route to the phase 2 destination. Option D is correct because the routing table does not show any routes to the phase 2 destination networks, which indicates that add-route is disabled in the phase 1 configuration. This option controls whether the FortiGate adds a static route to the phase 2 destination network using the tunnel interface as the gateway. Option A is incorrect because IPSec tunnel aggregation is a feature that allows multiple phase 2 selectors to share a single phase 1 tunnel, reducing the number of tunnels and improving performance. This feature is not related to the routing table or the phase 1 configuration. Option C is incorrect because OSPF is a dynamic routing protocol that can run over IPSec tunnels, but it requires additional configuration on the FortiGate and the peer device. This option is not related to the routing table or the phase 1 configuration.

Topics

#IPSec#net-device#add-route#routing table analysis

Community Discussion

No community discussion yet for this question.

Full NSE7_EFW-7.2 Practice