Frage 1
Antworten
-
Auto discovery VPN
-
Active Directory VPN
-
Active Direct VPN
Frage 2
Frage
Which VPN topology does not allow direct communication between spokes?
Antworten
-
a. Partial mesh
-
b. Hub-and-spoke
Frage 3
Frage
Which VPN topology is the most fault tolerant?
Antworten
-
a. Full mesh
-
b. Hub-and-spoke
Frage 4
Frage
FortiGate operation mode: NAT and transparent
L2TP-over—lPsec: Yes
GRE—over—lPsec: No
Routing protocols: No
Number of policies per VPN: One policy controls both traffic directions
Frage 5
Frage
FortiGate operation mode: Only NAT
L2TP-over—lPsec: Yes
GRE—over—lPsec: Yes
Routing protocols: Yes
Number of policies per VPN: Two policies (usually)—one for each direction
Frage 6
Frage
Transparent mode supports only policy-based VPNs
Frage 7
Frage
Generally, try to use policy-based because it offers more flexibility and control.
Frage 8
Frage
Traffic must be routed to the lPsec virtual network interface.
Usually two firewall policies with the Action set to ACCEPT are required (one per direction).
Frage 9
Frage
One firewall policy with the Action set to lPsec is required.
By default, hidden on the GUI. To show.
Frage 10
Frage
Wizard vpn creates only route-based VPNs
Frage 11
Frage
SD-WAN feature can also be used for VPN redundancy.
Frage 12
Frage
[blank_start]1-[blank_end] Add one phase 1 configuration for each tunnel. Dead peer detection (DPD) must be enabled on both ends.
[blank_start]2-[blank_end] Add at least one phase 2 definition for each phase 1.
[blank_start]3-[blank_end] Add one static route for each path. Use distance or priority to select primary routes over backup routes. Alternatively, use dynamic routing.
[blank_start]4-[blank_end] Configure firewall policies for each lPsec interface.
Frage 13
Frage
When configuring policy-based VPN, what option do you need to select for the Action setting?
Frage 14
Frage
Which of the following statements about route-based VPN is correct?
Frage 15
Frage
diagnose vpn tunnel list - command to verify if traffic is offloaded.
Frage 16
Frage
Keeping a real-time debug running on the background of a FortiGate for a long time it is necessary some times.
Frage 17
Frage 18
Frage
Which one of the following messages indicates that both ingress and egress ESP packets will be offloaded?
Antworten
-
a.npu_flag=00
-
b.npu_flag=03
Frage 19
Frage
If you enable NAT in the firewall policy for VPN, which of the following issues may occur?