nerdexam
Fortinet

NSE8_812 · Question #200

A network administrator has been tasked with modifying the existing dial-up IPsec VPN infrastructure to detect the path quality to the remote endpoints. After applying the configuration shown in the…

The correct answer is A. SLA link monitoring does not work with the net-device setting. See the full explanation below for the reasoning.

Question

A network administrator has been tasked with modifying the existing dial-up IPsec VPN infrastructure to detect the path quality to the remote endpoints. After applying the configuration shown in the configuration exhibit, the VPN clients can still connect and access the protected 172.16.205.0/24 network, but no SLA information shows up for the client tunnels when issuing the diagnose sys link-monitor tunnel all command on the FortiGate CLI. What is wrong with the configuration?

Options

  • ASLA link monitoring does not work with the net-device setting.
  • BThe admin needs to disable the mode-cfg setting.
  • CIPsec Phase 1 interface has to be configured in IPsec main mode.
  • DIt is necessary to use the IKEv2 protocol in this situation.

How the community answered

(40 responses)
  • A
    73% (29)
  • B
    8% (3)
  • C
    5% (2)
  • D
    15% (6)

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice