Refer to the exhibits.
A customer has deployed a FortiGate with iBGP and eBGP routing enabled. HQ is receiving routes over eBGP from ISP 2; however, only certain routes are showing up in the routing table-Assume that BGP is working perfectly and that the only possible modifications to the routing table are solely due to the prefix list that is applied on HQ.
Given the exhibits, which two routes will be active in the routing table on the HQ firewall? (Choose two.)
Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.
Dmust be set to enable add-route, which is the command that actually injects the IKE routes.
Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.
The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.
References:
Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0
Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0
Krystal
27 days agoTashia
9 days agoChristiane
1 months agoStevie
1 days agoDarrin
4 days agoAmira
17 days agoEzekiel
1 months agoMila
3 days agoDylan
12 days agoLorita
14 days agoTerrilyn
2 months agoSarah
9 days agoCarey
12 days agoLajuana
1 months agoMickie
1 months agoHana
2 months agoJovita
2 months agoPaulene
2 months agoRolande
2 months agoWillow
2 months agoMatthew
1 months agoMalcom
1 months agoMable
2 months agoGabriele
2 months agoAndra
2 months agoLeota
2 months agoReita
2 months agoGeorgeanna
2 months agoVallie
2 months agoCruz
2 months ago