nerdexam
Fortinet

NSE8_812 · Question #86

Refer to the exhibit. A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO). OSPF is used to redistribute routes between the offices. After deployment, a server with IP…

The correct answer is B. A directly connected subnet is being partially superseded by an OSPF redistributed subnet. See the full explanation below for the reasoning.

Question

Refer to the exhibit. A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO). OSPF is used to redistribute routes between the offices. After deployment, a server with IP address 10.10.10.35 located on the DMZ network of the BO FortiGate, was reported unreachable from hosts located on the LAN network of the same FortiGate. Referring to the exhibit, which statement is true?

Options

  • AThe ICMP packets are being blocked by an implicit deny policy.
  • BA directly connected subnet is being partially superseded by an OSPF redistributed subnet.
  • CEnabling NAT on the VPN firewall policy will solve the problem.
  • DThe incoming access list should have an accept action instead of a deny action to solve the problem.

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    80% (37)
  • C
    11% (5)
  • D
    2% (1)

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice