Q: 8
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic. Which DPD mode on FortiGate meets this requirement?
Options
Discussion
Option B is correct here. "On Idle" specifically sends DPD probes only when there's no inbound traffic, matching the question's condition. Option D is a common trap since "On Demand" would be more for manual or general inactivity, not just inbound. Feel free to correct me if I'm off.
Option B
B. only sends probes if inbound traffic goes quiet. That's exactly what the question wants.
B tbh
Makes sense to go with B here. "On Idle" fits because it sends DPD probes only if there's no inbound traffic.
Option B matches the requirement. On Idle sends DPD probes only if there’s no inbound traffic. That lines up with what the question is asking, pretty sure that’s how FortiGate handles it. Someone correct me if I’m missing a nuance.
C or D? Pretty sure I saw similar phrasing in the official guide and practice test.
B
Makes sense, B fits what they're asking. "On Idle" sends DPD probes if no inbound traffic is coming through, so that's exactly what the scenario describes. Pretty sure D is for manual checks or when there's no traffic at all. Anyone disagree?
C vs D? C is just off, but D is a trap here. It's B for sure.
Be respectful. No spam.