QuestionQ17

Advanced IPsec

Refer to the exhibit.

Question Image

The network diagram depicts adding Site 2, whose network segment overlaps, to the existing VPN IPsec connection between the hub and Site 1.

Which IPsec phase 2 configuration must be made on the FortiGate hub to enable equal-cost multi-path (ECMP) routing when multiple remote sites connect using overlapping subnets?

  • A Set route-overlap to either use-new or use-old
  • B Set route-overlap to allow
  • C set net-device to ecmp
  • D Set multipath to enable
Explanation

The IPsec phase 2 route-overlap option must be set to allow. This preserves overlapping remote routes so equal-cost paths for the same destination prefix can coexist. use-old suppresses the new route, while use-new removes the existing route, preventing ECMP across both VPN connections.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!