Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE8_812 Topic 1 Question 14 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 14
Topic #: 1
[All NSE8_812 Questions]

Refer to the exhibits.

A customer has deployed a FortiGate with iBGP and eBGP routing enabled. HQ is receiving routes over eBGP from ISP 2; however, only certain routes are showing up in the routing table-Assume that BGP is working perfectly and that the only possible modifications to the routing table are solely due to the prefix list that is applied on HQ.

Given the exhibits, which two routes will be active in the routing table on the HQ firewall? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, D, E

Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.

Dmust be set to enable add-route, which is the command that actually injects the IKE routes.

Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.

The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.

References:

Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0

Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0


Contribute your Thoughts:

Hana
4 days ago
I'm not sure about the routes. Can someone explain why A and D are the correct choices?
upvoted 0 times
...
Jovita
6 days ago
I agree with Paulene. Those routes seem to match the prefix list applied on HQ.
upvoted 0 times
...
Paulene
8 days ago
I think the active routes are A) 172.16.204.128/25 and D) 172.16.204.64/27.
upvoted 0 times
...
Rolande
11 days ago
I'm not sure about the routes, but I think we need to carefully analyze the prefix list to determine the active routes.
upvoted 0 times
...
Willow
11 days ago
Hmm, the prefix list is the key here. Let's see, 172.16.204.128/25 and 172.16.204.64/27 should be the active routes based on the information provided.
upvoted 0 times
...
Vallie
13 days ago
I agree with you, Cruz. Those routes seem to match the criteria based on the prefix list applied.
upvoted 0 times
...
Cruz
19 days ago
I think the active routes will be 172.16.204.128/25 and 172.16.204.64/27.
upvoted 0 times
...

Save Cancel