nerdexam
Fortinet

NSE8_812 · Question #25

Refer to the exhibit. To facilitate a large-scale deployment of SD-WAN/ADVPN with FortiGate devices, you are tasked with configuring the FortiGate devices to support injecting of IKE routes on the…

The correct answer is B. set mode-cfg enable D. set add-route enable E. set mode-cfg-allow-client-selector enable. See the full explanation below for the reasoning.

Question

Refer to the exhibit. To facilitate a large-scale deployment of SD-WAN/ADVPN with FortiGate devices, you are tasked with configuring the FortiGate devices to support injecting of IKE routes on the ADVPN shortcut tunnels. Which three commands must be added or changed for the FortiGate spoke config vpn ipsec phase1-interface options referenced in the exhibit for the VPN interface to enable this capability? (Choose three.)

Options

  • Aset net-device disable
  • Bset mode-cfg enable
  • Cset ike-version 1
  • Dset add-route enable
  • Eset mode-cfg-allow-client-selector enable

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    79% (26)
  • C
    15% (5)

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice