QuestionQ26

Network Security

Refer to the following exhibits.

Question Image

Question Image

Which two statements regarding the IPsec VPN configuration and IPsec VPN tunnel status are true?

Choose two
  • A FortiGate does not install IPsec static routes for remote protected networks in the routing table.
  • B The phase 1 configuration supports the network-overlay setting.
  • C FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.
  • D Dead peer detection is disabled.
Explanation

With add-route disabled, FortiGate does not automatically install a route to a peer destination selector. The Phase 1 configuration uses IKEv2, which supports the network-overlay setting. Dead peer detection is active in on-demand mode, as indicated by dpd: mode=on-demand on=1.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!