Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE8_812 Topic 1 Question 14 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 14
Topic #: 1
[All NSE8_812 Questions]

Refer to the exhibits.

A customer has deployed a FortiGate with iBGP and eBGP routing enabled. HQ is receiving routes over eBGP from ISP 2; however, only certain routes are showing up in the routing table-Assume that BGP is working perfectly and that the only possible modifications to the routing table are solely due to the prefix list that is applied on HQ.

Given the exhibits, which two routes will be active in the routing table on the HQ firewall? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, D, E

Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.

Dmust be set to enable add-route, which is the command that actually injects the IKE routes.

Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.

The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.

References:

Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0

Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0


Contribute your Thoughts:

Terrilyn
7 days ago
Wait, what's that weird format for the C option? 172,620,64,27? That can't be right. Gotta be careful with the formatting on these tricky questions.
upvoted 0 times
...
Hana
13 days ago
I'm not sure about the routes. Can someone explain why A and D are the correct choices?
upvoted 0 times
...
Jovita
15 days ago
I agree with Paulene. Those routes seem to match the prefix list applied on HQ.
upvoted 0 times
...
Paulene
17 days ago
I think the active routes are A) 172.16.204.128/25 and D) 172.16.204.64/27.
upvoted 0 times
...
Rolande
20 days ago
I'm not sure about the routes, but I think we need to carefully analyze the prefix list to determine the active routes.
upvoted 0 times
...
Willow
20 days ago
Hmm, the prefix list is the key here. Let's see, 172.16.204.128/25 and 172.16.204.64/27 should be the active routes based on the information provided.
upvoted 0 times
Gabriele
4 hours ago
Yes, those are the routes that will be active in the routing table.
upvoted 0 times
...
Andra
1 days ago
I agree, 172.16.204.128/25 and 172.16.204.64/27 are the correct routes.
upvoted 0 times
...
Leota
2 days ago
So, only those two routes will be in the routing table at HQ.
upvoted 0 times
...
Reita
3 days ago
That makes sense, those are the routes allowed by the prefix list.
upvoted 0 times
...
Georgeanna
5 days ago
I agree, 172.16.204.128/25 and 172.16.204.64/27 are the active routes.
upvoted 0 times
...
...
Vallie
22 days ago
I agree with you, Cruz. Those routes seem to match the criteria based on the prefix list applied.
upvoted 0 times
...
Cruz
28 days ago
I think the active routes will be 172.16.204.128/25 and 172.16.204.64/27.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77