NSE7_EFW-7.2 · Question #46
Refer to the exhibit, which shows a partial touting table. What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)
The correct answer is B. net-device is enabled in the tunnel IPSec phase 1 configuration D. add-route is disabled in the tunnel IPSec phase 1 configuration. Option B is correct because the routing table shows that the tunnel interfaces have a netmask of 255.255.255.255, which indicates that net-device is enabled in the phase 1 configuration. This option allows the FortiGate to use the tunnel interface as a next-hop for routing…
Question
Refer to the exhibit, which shows a partial touting table. What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)
Exhibit
Options
- AIPSec Tunnel aggregation is configured
- Bnet-device is enabled in the tunnel IPSec phase 1 configuration
- COSPI is configured to run over IPSec.
- Dadd-route is disabled in the tunnel IPSec phase 1 configuration.
How the community answered
(38 responses)- A5% (2)
- B82% (31)
- C13% (5)
Explanation
Option B is correct because the routing table shows that the tunnel interfaces have a netmask of 255.255.255.255, which indicates that net-device is enabled in the phase 1 configuration. This option allows the FortiGate to use the tunnel interface as a next-hop for routing, without adding a route to the phase 2 destination. Option D is correct because the routing table does not show any routes to the phase 2 destination networks, which indicates that add-route is disabled in the phase 1 configuration. This option controls whether the FortiGate adds a static route to the phase 2 destination network using the tunnel interface as the gateway. Option A is incorrect because IPSec tunnel aggregation is a feature that allows multiple phase 2 selectors to share a single phase 1 tunnel, reducing the number of tunnels and improving performance. This feature is not related to the routing table or the phase 1 configuration. Option C is incorrect because OSPF is a dynamic routing protocol that can run over IPSec tunnels, but it requires additional configuration on the FortiGate and the peer device. This option is not related to the routing table or the phase 1 configuration.
Topics
Community Discussion
No community discussion yet for this question.
