QuestionQ7

Network Security

Refer to the exhibit.

Question Image

Which configuration change is necessary if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

  • A type must be set to static.
  • B mode-cfg must be enabled.
  • C exchange-interface-ip must be enabled.
  • D add-route must be disabled.
Explanation

For a dynamic dial-up IPsec VPN that exchanges routes through a dynamic routing protocol, add-route must be disabled so FortiGate does not automatically install routes from negotiated IPsec selectors. Route discovery and selection are instead handled by the dynamic routing protocol.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!