Fortinet
NSE7_SDW-7.2 · Question #38
Refer to the exhibit. Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?
The correct answer is D. add-route must be disabled. For using "non ike" routes (for example BGP/static and so on) you must do disable the add-route that inject automatically kernel route based on p2 selectors from the remote site.
SD-WAN Deployment and Configuration
Question
Refer to the exhibit. Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?
Exhibit
Options
- Atype must be set to static.
- Bmode-cfg must be enabled.
- Cexchange-interface-ip must be enabled.
- Dadd-route must be disabled.
How the community answered
(22 responses)- A14% (3)
- B9% (2)
- C5% (1)
- D73% (16)
Explanation
For using "non ike" routes (for example BGP/static and so on) you must do disable the add-route that inject automatically kernel route based on p2 selectors from the remote site.
Topics
#IPsec configuration#dynamic routing#add-route#responder FortiGate
Community Discussion
No community discussion yet for this question.
