Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE8_812 Topic 1 Question 14 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 14
Topic #: 1
[All NSE8_812 Questions]

Refer to the exhibits.

A customer has deployed a FortiGate with iBGP and eBGP routing enabled. HQ is receiving routes over eBGP from ISP 2; however, only certain routes are showing up in the routing table-Assume that BGP is working perfectly and that the only possible modifications to the routing table are solely due to the prefix list that is applied on HQ.

Given the exhibits, which two routes will be active in the routing table on the HQ firewall? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, D, E

Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.

Dmust be set to enable add-route, which is the command that actually injects the IKE routes.

Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.

The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.

References:

Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0

Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0


Contribute your Thoughts:

Krystal
27 days ago
Wait, did they accidentally include a picture of a cat instead of the actual routing table? I'm starting to doubt the validity of this entire question.
upvoted 0 times
Tashia
9 days ago
I think the picture is just for reference, not the actual routing table.
upvoted 0 times
...
...
Christiane
1 months ago
Is it just me, or does this prefix list look like something a toddler would come up with? I bet the exam writers are having a good laugh at our expense on this one.
upvoted 0 times
Stevie
1 days ago
Definitely. It's all about understanding how the prefix list is filtering the routes.
upvoted 0 times
...
Darrin
4 days ago
I think the key is to focus on the subnet masks and match them with the routes.
upvoted 0 times
...
Amira
17 days ago
Yeah, I agree. These prefixes are all over the place.
upvoted 0 times
...
...
Ezekiel
1 months ago
Ah, the old 'choose two' trick. Easy peasy, I'm going with A and D. Can't wait to ace this exam and show off my BGP expertise to my coworkers!
upvoted 0 times
Mila
3 days ago
Dylan: Let's hope we both ace the exam with our BGP knowledge!
upvoted 0 times
...
Dylan
12 days ago
User 2: Yeah, those routes look like they would be active in the routing table.
upvoted 0 times
...
Lorita
14 days ago
User 1: I think you're right, A and D seem like the correct choices.
upvoted 0 times
...
...
Terrilyn
2 months ago
Wait, what's that weird format for the C option? 172,620,64,27? That can't be right. Gotta be careful with the formatting on these tricky questions.
upvoted 0 times
Sarah
9 days ago
Thanks for pointing that out, it's always good to double-check the information provided in the options.
upvoted 0 times
...
Carey
12 days ago
So, the correct routes in the routing table are A) 172.16.204.128/25 and D) 172.16.204.64/27.
upvoted 0 times
...
Lajuana
1 months ago
I agree, the format is definitely incorrect. It's important to pay attention to those details.
upvoted 0 times
...
Mickie
1 months ago
Yeah, that does look strange. It should be 172.16.204.27 instead of 172,620,64,27.
upvoted 0 times
...
...
Hana
2 months ago
I'm not sure about the routes. Can someone explain why A and D are the correct choices?
upvoted 0 times
...
Jovita
2 months ago
I agree with Paulene. Those routes seem to match the prefix list applied on HQ.
upvoted 0 times
...
Paulene
2 months ago
I think the active routes are A) 172.16.204.128/25 and D) 172.16.204.64/27.
upvoted 0 times
...
Rolande
2 months ago
I'm not sure about the routes, but I think we need to carefully analyze the prefix list to determine the active routes.
upvoted 0 times
...
Willow
2 months ago
Hmm, the prefix list is the key here. Let's see, 172.16.204.128/25 and 172.16.204.64/27 should be the active routes based on the information provided.
upvoted 0 times
Matthew
1 months ago
Exactly, the prefix list is filtering out the other routes.
upvoted 0 times
...
Malcom
1 months ago
Yes, those two routes should be the ones showing up in the routing table.
upvoted 0 times
...
Mable
2 months ago
I agree, 172.16.204.128/25 and 172.16.204.64/27 are the active routes.
upvoted 0 times
...
Gabriele
2 months ago
Yes, those are the routes that will be active in the routing table.
upvoted 0 times
...
Andra
2 months ago
I agree, 172.16.204.128/25 and 172.16.204.64/27 are the correct routes.
upvoted 0 times
...
Leota
2 months ago
So, only those two routes will be in the routing table at HQ.
upvoted 0 times
...
Reita
2 months ago
That makes sense, those are the routes allowed by the prefix list.
upvoted 0 times
...
Georgeanna
2 months ago
I agree, 172.16.204.128/25 and 172.16.204.64/27 are the active routes.
upvoted 0 times
...
...
Vallie
2 months ago
I agree with you, Cruz. Those routes seem to match the criteria based on the prefix list applied.
upvoted 0 times
...
Cruz
2 months ago
I think the active routes will be 172.16.204.128/25 and 172.16.204.64/27.
upvoted 0 times
...

Save Cancel