New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCSS_EFW_AD-7.6 Exam - Topic 3 Question 2 Discussion

Actual exam question for Fortinet's FCSS_EFW_AD-7.6 exam
Question #: 2
Topic #: 3
[All FCSS_EFW_AD-7.6 Questions]

Refer to the exhibit, which shows a corporate network and a new remote office network.

An administrator must integrate the new remote office network with the corporate enterprise network.

What must the administrator do to allow routing between the two networks?

Show Suggested Answer Hide Answer
Suggested Answer: D

In this scenario, the corporate network and the new remote office network need to communicate over the Internet, which requires a secure and dynamic routing method. Since both networks are using OSPF (Open Shortest Path First) as the routing protocol, the best approach is to establish an OSPF over IPsec VPN to ensure secure and dynamic route propagation.

OSPF is already running on the corporate network, and extending it over an IPsec tunnel allows dynamic route exchange between the corporate FortiGate and the remote office FortiGate. IPsec provides encryption for traffic over the Internet, ensuring secure communication. OSPF over IPsec eliminates the need for manual static routes, allowing automatic route updates if networks change.

The new remote office's 192.168.1.0/24 subnet will be advertised dynamically to the corporate network without additional configuration.


Contribute your Thoughts:

0/2000 characters
Carole
2 months ago
Agreed, static route is the simplest solution!
upvoted 0 times
...
Cassi
2 months ago
Wait, can you really use OSPF over IPsec?
upvoted 0 times
...
Peggy
2 months ago
Definitely need that static route!
upvoted 0 times
...
Hillary
3 months ago
I think virtual links are unnecessary here.
upvoted 0 times
...
Jerry
3 months ago
BGP is overkill for this setup.
upvoted 0 times
...
Alease
3 months ago
Virtual links sound familiar, but I can't remember if they apply here. I might have to go with the static route option since it seems straightforward.
upvoted 0 times
...
Vicky
3 months ago
I practiced a similar question where OSPF was involved, but I can't recall if it was over IPsec. That makes me lean towards option D being a possibility.
upvoted 0 times
...
Angelica
4 months ago
I'm not entirely sure, but I feel like BGP is more for larger networks. I wonder if it’s really necessary here.
upvoted 0 times
...
Mira
4 months ago
I think I remember something about static routes being a common solution for connecting different networks, so option B might be the right choice.
upvoted 0 times
...
Amina
4 months ago
I'm not too familiar with FortiGate devices, but based on the information provided, I think option B is the way to go. A static route should be the easiest way to integrate the new remote office network.
upvoted 0 times
...
Glenna
4 months ago
I'm leaning towards option D with OSPF over IPsec. That way we can have a more dynamic routing protocol between the networks and secure the connection with IPsec.
upvoted 0 times
...
Jackie
4 months ago
Option B sounds like the simplest solution to me. Configuring a static route on the corporate FortiGate seems straightforward and should get the job done.
upvoted 0 times
...
Gregoria
4 months ago
Hmm, I'm a bit confused. Wouldn't implementing BGP be a better option to dynamically route between the networks? I'm not sure about the virtual links or OSPF over IPsec.
upvoted 0 times
...
Linn
5 months ago
I think the key here is to integrate the two networks, so I'd go with option B and configure a static route on the corporate FortiGate device.
upvoted 0 times
...

Save Cancel