Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam FCSS_EFW_AD-7.6 Topic 3 Question 2 Discussion

Actual exam question for Fortinet's FCSS_EFW_AD-7.6 exam
Question #: 2
Topic #: 3
[All FCSS_EFW_AD-7.6 Questions]

Refer to the exhibit, which shows a corporate network and a new remote office network.

An administrator must integrate the new remote office network with the corporate enterprise network.

What must the administrator do to allow routing between the two networks?

Show Suggested Answer Hide Answer
Suggested Answer: D

In this scenario, the corporate network and the new remote office network need to communicate over the Internet, which requires a secure and dynamic routing method. Since both networks are using OSPF (Open Shortest Path First) as the routing protocol, the best approach is to establish an OSPF over IPsec VPN to ensure secure and dynamic route propagation.

OSPF is already running on the corporate network, and extending it over an IPsec tunnel allows dynamic route exchange between the corporate FortiGate and the remote office FortiGate. IPsec provides encryption for traffic over the Internet, ensuring secure communication. OSPF over IPsec eliminates the need for manual static routes, allowing automatic route updates if networks change.

The new remote office's 192.168.1.0/24 subnet will be advertised dynamically to the corporate network without additional configuration.


Contribute your Thoughts:

Mira
5 days ago
I think I remember something about static routes being a common solution for connecting different networks, so option B might be the right choice.
upvoted 0 times
...
Amina
11 days ago
I'm not too familiar with FortiGate devices, but based on the information provided, I think option B is the way to go. A static route should be the easiest way to integrate the new remote office network.
upvoted 0 times
...
Glenna
16 days ago
I'm leaning towards option D with OSPF over IPsec. That way we can have a more dynamic routing protocol between the networks and secure the connection with IPsec.
upvoted 0 times
...
Jackie
21 days ago
Option B sounds like the simplest solution to me. Configuring a static route on the corporate FortiGate seems straightforward and should get the job done.
upvoted 0 times
...
Gregoria
26 days ago
Hmm, I'm a bit confused. Wouldn't implementing BGP be a better option to dynamically route between the networks? I'm not sure about the virtual links or OSPF over IPsec.
upvoted 0 times
...
Linn
1 months ago
I think the key here is to integrate the two networks, so I'd go with option B and configure a static route on the corporate FortiGate device.
upvoted 0 times
...

Save Cancel