Free NSE7_EFW-7.2 Exam Braindumps (page: 4)

Page 3 of 15

Exhibit.



Refer to the exhibit, which shows a partial touting table What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

  1. IPSec Tunnel aggregation is configured
  2. net-device is enabled in the tunnel IPSec phase 1 configuration
  3. OSPI is configured to run over IPSec.
  4. add-route is disabled in the tunnel IPSec phase 1 configuration.

Answer(s): B,D

Explanation:

Option B is correct because the routing table shows that the tunnel interfaces have a netmask of

255.255.255.255, which indicates that net-device is enabled in the phase 1 configuration. This option allows the FortiGate to use the tunnel interface as a next-hop for routing, without adding a route to the phase 2 destination.
Option D is correct because the routing table does not show any routes to the phase 2 destination networks, which indicates that add-route is disabled in the phase 1 configuration. This option controls whether the FortiGate adds a static route to the phase 2 destination network using the tunnel interface as the gateway.
Option A is incorrect because IPSec tunnel aggregation is a feature that allows multiple phase 2 selectors to share a single phase 1 tunnel, reducing the number of tunnels and improving performance. This feature is not related to the routing table or the phase 1 configuration. Option C is incorrect because OSPF is a dynamic routing protocol that can run over IPSec tunnels, but it requires additional configuration on the FortiGate and the peer device. This option is not related to the routing table or the phase 1 configuration.


Reference:

=
1: Technical Tip: `set net-device' new route-based IPsec logic2
2: Adding a static route5
3: IPSec VPN concepts6
4: Dynamic routing over IPsec VPN7



Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?

  1. Enable AD-VPN in IPsec phase 1
  2. Disable add-route on hub
  3. Configure IP addresses on IPsec virtual interlaces
  4. Set protected network to all

Answer(s): A

Explanation:

To enable AD-VPN, you need to edit an SD-WAN overlay template and enable the Auto-Discovery VPN toggle. This will automatically add the required settings to the IPsec template and the BGP template. You cannot enable AD-VPN directly in the IPsec phase 1 settings using VPN Manager.


Reference:

ADVPN | FortiManager 7.2.0 - Fortinet Documentation



Exhibit.



Refer to the exhibit, which provides information on BGP neighbors.
Which can you conclude from this command output?

  1. The router are in the number to match the remote peer.
  2. You must change the AS number to match the remote peer.
  3. BGP is attempting to establish a TCP connection with the BGP peer.
  4. The bfd configuration to set to enable.

Answer(s): C

Explanation:

The BGP state is "Idle", indicating that BGP is attempting to establish a TCP connection with the peer. This is the first state in the BGP finite state machine, and it means that no TCP connection has been established yet. If the TCP connection fails, the BGP state will reset to either active or idle, depending on the configuration.


Reference:

You can find more information about BGP states and troubleshooting in the following Fortinet Enterprise Firewall 7.2 documents:
Troubleshooting BGP
How BGP works



Exhibit.



Refer to the exhibit, which contains the partial ADVPN configuration of a spoke.

Which two parameters must you configure on the corresponding single hub? (Choose two.)

  1. Set auto-discovery-sender enable
  2. Set ike-version 2
  3. Set auto-discovery-forwarder enable
  4. Set auto-discovery-receiver enable

Answer(s): A,B

Explanation:

For an ADVPN spoke configuration shown, the corresponding hub must have auto-discovery-sender enabled to send shortcut advertisement messages to the spokes. Also, the hub would need to have auto-discovery-forwarder enabled if it is to forward on those shortcut advertisements to other spokes. This allows the hub to inform all spokes about the best path to reach each other. The ike- version does not need to be reconfigured on the hub if it's already set to version 2 and auto- discovery-receiver is not necessary on the hub because it's the one sending the advertisements, not receiving.


Reference:

FortiOS Handbook - ADVPN






Post your Comments and Discuss Fortinet NSE7_EFW-7.2 exam with other Community members:

NSE7_EFW-7.2 Discussions & Posts