Fortinet
NSE8_812 · Question #31
The device IP 10.1.100.40 downloads a file from the FTP server IP 192.168.4.50. Referring to the exhibit, what will be the traffic flow behavior if ADVPN is configured in this environment? Refer to…
The correct answer is D. Spoke1 will establish an ADVPN shortcut to Spoke2. https://docs.fortinet.com/document/fortigate/7.2.5/administration-guide/448665/udp-hole-punching-for-spokes-behind-nat
Secure VPN Solutions (IPsec and SSL)
Question
The device IP 10.1.100.40 downloads a file from the FTP server IP 192.168.4.50. Referring to the exhibit, what will be the traffic flow behavior if ADVPN is configured in this environment?
Refer to the exhibit:
[Image showing a Hub (22.1.1.1), NAT Device1 (12.1.1.2) with Spoke1 (10.1.100.40), and NAT Device2 (55.1.1.2) with Spoke2 (192.168.4.50). NAT devices connect to the Hub. Spoke1 and Spoke2 are behind NAT devices.]
Options
- AAll the session traffic will pass through the Hub
- BThe TCP port 21 must be allowed on the NAT Device2
- CADVPN is not supported when spokes are behind NAT
- DSpoke1 will establish an ADVPN shortcut to Spoke2
How the community answered
(21 responses)- A5% (1)
- B14% (3)
- C5% (1)
- D76% (16)
Explanation
Topics
#ADVPN#NAT traversal#spoke-to-spoke shortcut#IPsec
Community Discussion
No community discussion yet for this question.