Join the discussion
Question 15/98
You configure the overlay tunnels for an SD-WAN hub-and-spoke topology defined with IPsec tunnels, BGP on loopback, and dynamic BGP.
Which two are recommended IPsec settings for this topology? (Choose two answers.)
Which two are recommended IPsec settings for this topology? (Choose two answers.)
Correct Answer: C,D
The SD-WAN 7.6 Enterprise Administrator Study Guide identifies the recommended BGP-on-loopback IPsec settings. For branches, it specifies:
"Static tunnel type (remote end IP address is known)."
"net-device enable."
Enabling net-device on the spoke creates a kernel interface for the tunnel. This assists with tunnel monitoring and management and is required to support ADVPN shortcut tunnels. Dynamic BGP establishes on-demand BGP peerings between spokes after an ADVPN shortcut is created; therefore, the spoke must support those dynamic shortcut interfaces. This makes option C correct.
The spoke should also configure localid. The FortiOS 7.6 Administrator Study Guide explains: "Local ID: if the peer accepts a specific peer ID, type that same peer ID in this field." The local ID supplies the spoke's IKE identity to the dial-up hub, allowing the hub to identify and authenticate the connecting spoke correctly.
Therefore, option D is correct.
Option A reverses the recommended roles. The hub must use a dynamic tunnel type because it operates as the dial-up server and does not require every spoke's changing public gateway address in advance.
Option B is also incorrect. The guide states: "There is no need to configure any tunnel IP address, so the IKE Mode Config is not used." BGP on loopback uses the loopback address and exchange-interface-ip instead of IKE mode configuration.
References: SD-WAN 7.6 Enterprise Administrator Study Guide, SD-WAN Overlay Design and Best Practices, pages 118-119 and 122; FortiOS 7.6 Administrator Study Guide, IPsec VPN - Phase 1 Network Settings, page 375; FortiOS 7.6 - BGP on loopback.
"Static tunnel type (remote end IP address is known)."
"net-device enable."
Enabling net-device on the spoke creates a kernel interface for the tunnel. This assists with tunnel monitoring and management and is required to support ADVPN shortcut tunnels. Dynamic BGP establishes on-demand BGP peerings between spokes after an ADVPN shortcut is created; therefore, the spoke must support those dynamic shortcut interfaces. This makes option C correct.
The spoke should also configure localid. The FortiOS 7.6 Administrator Study Guide explains: "Local ID: if the peer accepts a specific peer ID, type that same peer ID in this field." The local ID supplies the spoke's IKE identity to the dial-up hub, allowing the hub to identify and authenticate the connecting spoke correctly.
Therefore, option D is correct.
Option A reverses the recommended roles. The hub must use a dynamic tunnel type because it operates as the dial-up server and does not require every spoke's changing public gateway address in advance.
Option B is also incorrect. The guide states: "There is no need to configure any tunnel IP address, so the IKE Mode Config is not used." BGP on loopback uses the loopback address and exchange-interface-ip instead of IKE mode configuration.
References: SD-WAN 7.6 Enterprise Administrator Study Guide, SD-WAN Overlay Design and Best Practices, pages 118-119 and 122; FortiOS 7.6 Administrator Study Guide, IPsec VPN - Phase 1 Network Settings, page 375; FortiOS 7.6 - BGP on loopback.
Add Comments
- Other Question (98q)
- Q1. Refer to the exhibit, which shows partial outputs from two routing debug commands. (Exhibi...
- Q2. Refer to the exhibit, which shows the omitted output of a session table entry. (Exhibit) W...
- Q3. Refer to the exhibit. (Exhibit) An administrator has configured a firewall policy to use p...
- Q4. Refer to the exhibit, which shows a partial output of a real-time LDAP debug. (Exhibit) Wh...
- Q5. Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug com...
- Q6. Refer to the exhibit, which shows the modified output of the routing kernel. (Exhibit) Whi...
- Q7. Refer to the exhibit, which shows a truncated output of a real-time LDAP debug. (Exhibit) ...
- Q8. Refer to the exhibit. (Exhibit) An IPsec VPN tunnel using IKEv2 was brought up successfull...
- Q9. Refer to the exhibit. (Exhibit) Partial output of the fssod daemon real-time debug command...
- Q10. Refer to the exhibit, which shows partial outputs from two routing debug commands. (Exhibi...
- Q11. You want to configure two static routes: one that references a zone and a second one that ...
- Q12. Refer to the exhibits, (Exhibit) which show the configuration on FortiGate and partial ses...
- Q13. Refer to the exhibit. (Exhibit) The output of the command diagnose vpn tunnels liar is sho...
- Q14. Refer to the exhibit. (Exhibit) The VDOM configuration on a FortiGate device is shown. You...
- Q15. You configure the overlay tunnels for an SD-WAN hub-and-spoke topology defined with IPsec ...
- Q16. Refer to the exhibit, which shows the omitted output of a session table entry. (Exhibit) W...
- Q17. Exhibit. (Exhibit) Refer to the exhibit, which shows two entries that were generated in th...
- Q18. Refer to the exhibit, which shows the output of a diagnose command. What can you conclude ...
- Q19. Refer to the exhibit, which shows the port1 interface configuration on FortiGate and parti...
- Q20. Refer to the exhibit, which shows partial outputs from two routing debug commands. (Exhibi...
- Q21. Refer to the exhibit. (Exhibit) The port1 interface configuration on FortiGate and partial...
- Q22. Refer to the exhibit, which shows a partial output from the get router info routing-table ...
- Q23. Refer to the exhibit, which a network topology and a partial routing table. (Exhibit) Fort...
- Q24. Exhibit. (Exhibit) Refer to the exhibit, which shows two entries that were generated in th...
- Q25. Refer to the exhibit, which shows the output of the command get router info bgp neighbors ...
- Q26. Which two protocol states indicate that traffic is bidirectional? (Choose two.)...
- Q27. What are two reasons you might see iprope_in check () check failed, drop when using the de...
- Q28. Refer to the exhibit. (Exhibit) The sniffer log on two FortiGate devices are shown. Based ...
- Q29. Refer to the exhibit, which a network topology and a partial routing table. (Exhibit) Fort...
- Q30. Refer to the exhibit, which shows the output of a BGP debug command. (Exhibit) What can yo...
- Q31. Exhibit 1. (Exhibit) Exhibit 2. (Exhibit) Refer to the exhibits, which show the configurat...
- Q32. Which statement about IKEv2 is true?
- Q33. Refer to the exhibit. (Exhibit) The partial output of diagnose sys session stat command is...
- Q34. Refer to the exhibit. (Exhibit) Partial output of command diagnose debug rating is shown. ...
- Q35. Refer to the exhibit, which shows the output of get router info ospf neighbor. (Exhibit) W...
- Q36. Exhibit. (Exhibit) Refer to the exhibit, which shows a partial output of diagnose hardware...
- Q37. Refer to the exhibit, which shows the output of a debug command. (Exhibit) Which two state...
- Q38. Refer to the exhibit. (Exhibit) Assuming a default configuration, which three statements a...
- Q39. Exhibit. (Exhibit) Refer to the exhibit, which shows the output of a diagnose command. Wha...
- Q40. Refer to the exhibit. (Exhibit) Which two statements about the output are true, considerin...
- Q41. In a transparent VDOM interface, what does the command set forward-domain < domain_ID &...
- Q42. Refer to the exhibit. (Exhibit) You want to configure SD-WAN on a network, as shown in the...
- Q43. Refer to the exhibit. Partial output of a real-time OSPF debug is shown. (Exhibit) Which t...
- Q44. Refer to the exhibit, which shows the output of the command get router info ospf neighbor....
- Q45. Refer to the exhibit, which shows the output o! the BGP database. (Exhibit) Which two stat...
- Q46. Refer to the exhibit. (Exhibit) The output from using the command diagnose debug applicati...
- Q47. An administrator wants to capture encrypted phase 2 traffic between two FotiGate devices u...
- Q48. What is the correct order of the IKEv2 request-and-response protocol?...
- Q49. Refer to the exhibit. (Exhibit) The partial output of FortiOS kernel slabs is shown. Which...
- Q50. A VPN tunnel is up. To monitor traffic flow, the administrator enters the following CLI co...
- Q51. Which two statements about an auxiliary session ate true? (Choose two.)...
- Q52. In the context of SD-WAN, the terms underlay and overlay are commonly used to categorize l...
- Q53. Refer to the exhibits. (Exhibit) The system administrator settings configured on the root ...
- Q54. You use the FortiManager SD-WAN overlay orchestrator to prepare an SD-WAN deployment. Usin...
- Q55. Which statement about IKEv2 is true?
- Q56. Which Iwo troubleshooting steps should you perform lf you encounter issues with intermitte...
- Q57. When you deploy SD-WAN, you can choose from several common designs. Each design best appli...
- Q58. Refer to the exhibit. (Exhibit) The port1 interface configuration on FortiGate and partial...
- Q59. Refer to the exhibits. (Exhibit) An administrator Is expecting to receive advertised route...
- Q60. Refer to the exhibit. (Exhibit) A partial output from an IKE real-time debug is shown The ...
- Q61. Refer to the exhibit, which shows a partial web filter profile configuration. (Exhibit) Th...
- Q62. What can cause an IKEv2 tunnel to go down after it was initially brought up successfully?...
- Q63. What are three characteristics of the provisioning templates available on FortiManager? (C...
- Q64. In a Security Fabric environment which three actions must you take to ensure successful co...
- Q65. Refer to the exhibit. (Exhibit) You update the spokes configuration of an existing auto-di...
- Q66. What are two reasons you might see iprope_in_check() check failed, drop when using the deb...
- Q67. Refer to the exhibit, which shows a session entry. (Exhibit) Which statement about this se...
- Q68. Refer to the exhibit, which shows one way communication of the downstream FortiGate with t...
- Q69. Which three common FortiGate-to-collector-agent connectivity issues can you identify using...
- Q70. Refer to the exhibit. (Exhibit) The modified output of live routing kemel is shown Which t...
- Q71. Refer to the exhibit. (Exhibit) Assuming a default configuration, which three statements a...
- Q72. If you configure set tcp-mss-sender and set tcp-mss-receiver in a firewall policy, how doe...
- Q73. Refer to the exhibit, which shows the output of get router info ospf neighbor. (Exhibit) W...
- Q74. Refer to the exhibit. (Exhibit) The partial output of a session table entry is shown. Whic...
- Q75. In which two slates is a given session categorized as ephemeral? (Choose two.)...
- Q76. The local OSPF router is unable to establish adjacency with a peer. Which two things shoul...
- Q77. Which two statements about application-layer test commands are true? (Choose two answers)...
- Q78. Refer to the exhibit, which shows the partial output of FortiOS kernel slabs. (Exhibit) Wh...
- Q79. You have a FortiGate configuration with three user-defined SD-WAN zones and two members in...
- Q80. Refer to the exhibits. (Exhibit) An OSPF peer is advertising route 172.16.52.0/24. The loc...
- Q81. Refer to the exhibit. (Exhibit) The exhibit shows the output of a session. Which two state...
- Q82. In IKEv2, which exchange establishes the first CHILD_SA?...
- Q83. Refer to the exhibit. (Exhibit) A network topology and a partial routing table are shown. ...
- Q84. Refer to the exhibit. (Exhibit) Which two observations can you make about the web filter t...
- Q85. Which two statements are true regarding heartbeat messages sent from an FSSO collector age...
- Q86. Refer to the exhibit. Partial output of a real-time OSPF debug is shown. (Exhibit) Which t...
- Q87. Refer to the exhibit. (Exhibit) An IPsec VPN tunnel is dropping, as shown by the debug out...
- Q88. Refer to the exhibit. (Exhibit) The output of a BGP debug command is shown. Why has the lo...
- Q89. Refer to the exhibit, which shows the partial output of FortiOS kernel slabs. (Exhibit) Wh...
- Q90. Which Iwo actions does FortiGate take after an administrator enables the auxiliary session...
- Q91. Refer to the exhibit. (Exhibit) Which Iwo statements about FortiGate behavior relating to ...
- Q92. Refer to the exhibit. (Exhibit) A partial output of diagnose npu up6 port-list on FortiGat...
- Q93. Refer to the exhibit. (Exhibit) Which three pieces of information does the diagnose sys to...
- Q94. Refer to the exhibit. (Exhibit) The output of the command diagnose vpn tunnel list is show...
- Q95. What are two reasons you might see iprope_in_check() check failed, drop when using the deb...
- Q96. Refer to the exhibit, which shows the output of diagnose sys session stat. (Exhibit) Which...
- Q97. Refer to the exhibit. (Exhibit) Which Iwo statements about FortiGate behavior relating to ...
- Q98. What can cause an IKEv2 tunnel to go down after it was initially brought up successfully?...
[×]
Download PDF File
Enter your email address to download Fortinet.NSE7_FSN_AR-7.6.v2026-07-09.q98.pdf
