Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE8_812 Topic 1 Question 14 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 14
Topic #: 1
[All NSE8_812 Questions]

Refer to the exhibit.

To facilitate a large-scale deployment of SD-WAN/ADVPN with FortiGate devices, you are tasked with configuring the FortiGate devices to support injecting of IKE routes on the ADVPN shortcut tunnels.

Which three commands must be added or changed to the FortiGate spoke config vpn ipsec phasei-interface options referenced in the exhibit for the VPN interface to enable this capability? (Choose three.)

Show Suggested Answer Hide Answer
Suggested Answer: B, D, E

Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.

Dmust be set to enable add-route, which is the command that actually injects the IKE routes.

Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.

The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.

References:

Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0

Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0


Contribute your Thoughts:

Jose
8 days ago
Haha, I love how the question is so specific. It's like they're really trying to trick us, but we're too smart for that, right guys?
upvoted 0 times
...
Pansy
9 days ago
Definitely, I'm leaning towards options B, D, and E. Setting mode-cfg to enable, adding-route to enable, and allowing the client selector seems like the way to go.
upvoted 0 times
...
Lashanda
10 days ago
I agree, the question is pretty clear. Based on the options, I think we need to look for commands that enable or configure the mode-cfg and IKE settings.
upvoted 0 times
...
Sang
11 days ago
Hmm, this question seems pretty straightforward. We need to enable the injection of IKE routes on the ADVPN shortcut tunnels, so the key commands are probably related to that functionality.
upvoted 0 times
...

Save Cancel