Fortinet
NSE8_810 · Question #46
Click the exhibit. A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO) and OSPF is used to redistribute routes between the offices. After deployment, a server with IP…
The correct answer is B. The incoming access list should have an accept action instead of a deny action to solve the problem. Explanation/Reference:
Advanced Routing and Switching
Question
Click the exhibit. A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO) and OSPF is used to redistribute routes between the offices. After deployment, a server with IP address 10.10.10.35 located on the DMZ network of the BO FortiGate, was reported unreachable from hosts located on the LAN network of the same FortiGate. Referring to the exhibit, which statement is true?
Exhibit
Options
- AThe ICMP packets are being blocked by an implicit deny policy.
- BThe incoming access list should have an accept action instead of a deny action to solve the problem.
- CA directly connected subnet is being partially superseded by an OSPF redistributed subnet.
- DEnabling NAT on the VPN firewall policy will solve the problem.
How the community answered
(32 responses)- A3% (1)
- B69% (22)
- C9% (3)
- D19% (6)
Explanation
Explanation/Reference:
Topics
#OSPF redistribution#IPsec VPN#routing conflict#access-list
Community Discussion
No community discussion yet for this question.
