Q: 8
An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic. Which DPD mode on FortiGate meets this requirement?
Options
Discussion
C or D? Pretty sure I saw similar phrasing in the official guide and practice test.
B
Had something like this in a mock, pretty sure it's B for DPD "on idle" mode.
Why would D not match if "on demand" sounds like probes only when needed? Isn’t that what the question is asking?
B tbh, C and D are tempting but 'On Idle' actually matches the no inbound traffic condition.
B not D. 'On Idle' sends probes only when no inbound traffic, D is a trap for demand-triggered.
I always used D for on-demand checks since it seems like probes only go out when necessary. D.
I think it should be D, On Demand. Sounds like FortiGate would send probes when needed, not all the time. Not 100% sure though!
Be respectful. No spam.