nerdexam
Fortinet

NSE7_EFW-7.2 · Question #7

Refer to the exhibit, which contains information about an IPsec VPN tunnel. What two conclusions can you draw from the command output? (Choose two.)

The correct answer is B. The IKE version is 2: This can be deduced from the presence of 'ver=2' in the output, which C. Both IPsec SAs are loaded on the kernel: This is indicated by the line 'npu flags=0x0/0'. From the command output shown in the exhibit: indicates that IKEv2 is being used. suggesting that no offload to NPU is occurring, and hence, both Security Associations are loaded onto the kernel for processing. Fortinet documentation specifies that the version of IKE (Internet…

FortiGate Advanced Routing and VPN

Question

Refer to the exhibit, which contains information about an IPsec VPN tunnel. What two conclusions can you draw from the command output? (Choose two.)

Exhibit

NSE7_EFW-7.2 question #7 exhibit

Options

  • ADead peer detection is set to enable
  • BThe IKE version is 2: This can be deduced from the presence of 'ver=2' in the output, which
  • CBoth IPsec SAs are loaded on the kernel: This is indicated by the line 'npu flags=0x0/0',
  • DForward error correction in phase 2 is set to enable

How the community answered

(66 responses)
  • A
    8% (5)
  • B
    77% (51)
  • D
    15% (10)

Explanation

From the command output shown in the exhibit: indicates that IKEv2 is being used. suggesting that no offload to NPU is occurring, and hence, both Security Associations are loaded onto the kernel for processing. Fortinet documentation specifies that the version of IKE (Internet Key Exchange) used and the loading of IPsec Security Associations can be verified through the diagnostic commands related

Topics

#IPsec SA#IKEv2#kernel SA#VPN diagnostics

Community Discussion

No community discussion yet for this question.

Full NSE7_EFW-7.2 Practice