An HA topology is using the following configuration:
Based on this configuration, how long will it take for a failover to be detected by the secondary cluster member?
Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.
Dmust be set to enable add-route, which is the command that actually injects the IKE routes.
Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.
The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.
References:
Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0
Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0
Sabra
2 months agoJunita
9 days agoKeena
14 days agoVerlene
15 days agoFiliberto
24 days agoEvangelina
2 months agoStanford
6 hours agoStephaine
3 days agoCassie
1 months agoGlory
2 months agoCarmelina
28 days agoPaz
1 months agoCarey
2 months agoRia
20 days agoKimbery
1 months agoLindy
2 months agoGolda
2 months agoChaya
2 months agoKendra
2 months agoChaya
3 months ago