Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE8_812 Exam - Topic 5 Question 62 Discussion

You have configured a Site-to-Site IPsec VPN tunnel between a FortiGate and a third-party device but notice that one of the error counters on the tunnel interface keeps increasing.Which two configuration options can resolve this problem? (Choose two.)
C) Enable DF-bit honoring in the global settings. and D) Adjust the MTU of the IPsec interface.
A) Enable Forward Error Correction (FEC) on the VPN interface for egress traffic.
B) Adjust the MTU of the physical interface to which the IPsec tunnel is bound.

Fortinet NSE8_812 Exam - Topic 5 Question 62 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 62
Topic #: 5
[All NSE8_812 Questions]

You have configured a Site-to-Site IPsec VPN tunnel between a FortiGate and a third-party device but notice that one of the error counters on the tunnel interface keeps increasing.

Which two configuration options can resolve this problem? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: C, D

Contribute your Thoughts:

0/2000 characters
Yoko
2 days ago
Wait, why would adjusting the physical interface MTU matter? Sounds odd.
upvoted 0 times
...
Hui
7 days ago
I think enabling DF-bit honoring could also fix it.
upvoted 0 times
...
Meghann
12 days ago
Definitely adjust the MTU of the IPsec interface. That usually helps!
upvoted 0 times
...
Aleshia
17 days ago
FEC sounds familiar, but I can't recall if it applies to this situation. I feel like it might be more about the MTU settings.
upvoted 0 times
...
Fidelia
23 days ago
I practiced a similar question where adjusting the MTU on the physical interface resolved a similar problem. Maybe that could work here too?
upvoted 0 times
...
Ellsworth
28 days ago
I'm not entirely sure, but I think enabling DF-bit honoring could also be a solution. It seems relevant to fragmentation issues.
upvoted 0 times
...
Keith
1 month ago
I remember we discussed MTU issues in class, so adjusting the MTU of the IPsec interface might help with those error counters.
upvoted 0 times
...

Save Cancel