nerdexam
Fortinet

NSE8_812 · Question #31

The device IP 10.1.100.40 downloads a file from the FTP server IP 192.168.4.50. Referring to the exhibit, what will be the traffic flow behavior if ADVPN is configured in this environment? Refer to…

The correct answer is D. Spoke1 will establish an ADVPN shortcut to Spoke2. https://docs.fortinet.com/document/fortigate/7.2.5/administration-guide/448665/udp-hole-punching-for-spokes-behind-nat

Secure VPN Solutions (IPsec and SSL)

Question

The device IP 10.1.100.40 downloads a file from the FTP server IP 192.168.4.50. Referring to the exhibit, what will be the traffic flow behavior if ADVPN is configured in this environment? Refer to the exhibit: [Image showing a Hub (22.1.1.1), NAT Device1 (12.1.1.2) with Spoke1 (10.1.100.40), and NAT Device2 (55.1.1.2) with Spoke2 (192.168.4.50). NAT devices connect to the Hub. Spoke1 and Spoke2 are behind NAT devices.]

Options

  • AAll the session traffic will pass through the Hub
  • BThe TCP port 21 must be allowed on the NAT Device2
  • CADVPN is not supported when spokes are behind NAT
  • DSpoke1 will establish an ADVPN shortcut to Spoke2

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    14% (3)
  • C
    5% (1)
  • D
    76% (16)

Explanation

https://docs.fortinet.com/document/fortigate/7.2.5/administration-guide/448665/udp-hole-punching-for-spokes-behind-nat

Topics

#ADVPN#NAT traversal#spoke-to-spoke shortcut#IPsec

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice