An HA topology is using the following configuration:
Based on this configuration, how long will it take for a failover to be detected by the secondary cluster member?
Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.
Dmust be set to enable add-route, which is the command that actually injects the IKE routes.
Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.
The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.
References:
Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0
Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0
Sabra
1 months agoKeena
23 hours agoVerlene
2 days agoFiliberto
11 days agoEvangelina
1 months agoCassie
18 days agoGlory
2 months agoCarmelina
15 days agoPaz
25 days agoCarey
2 months agoRia
7 days agoKimbery
28 days agoLindy
1 months agoGolda
1 months agoChaya
2 months agoKendra
2 months agoChaya
2 months ago