Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable
equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?Q: 1
Refer to the exhibit, which shows a network diagram showing the addition of site 2 with an
overlapping network segment to the existing VPN IPsec connection between the hub and site 1.
Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable
equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?
Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable
equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Refer to the exhibit, which shows a partial troubleshooting command output.
An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to
the output shown in the exhibit.
What can the administrator conclude?
An administrator is extensively using IPsec on FortiGate. Many tunnels show information similar to
the output shown in the exhibit.
What can the administrator conclude?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
An administrator is setting up an ADVPN configuration and wants to ensure that peer IDs are not
exposed during VPN establishment.
Which protocol can the administrator use to enhance security?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
An administrator must standardize the deployment of FortiGate devices across branches with
consistent interface roles and policy packages using FortiManager.
What is the recommended best practice for interface assignment in this scenario?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Refer to the exhibit, which contains a partial command output.
The administrator has configured BGP on FortiGate. The status of this new BGP configuration is
shown in the exhibit.
What configuration must the administrator consider next?
The administrator has configured BGP on FortiGate. The status of this new BGP configuration is
shown in the exhibit.
What configuration must the administrator consider next?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A company's guest internet policy, operating in proxy mode, blocks access to Artificial Intelligence
Technology sites using FortiGuard. However, a guest user accessed a page in this category using port
8443.
Which configuration changes are required for FortiGate to analyze HTTPS traffic on nonstandard
ports like 8443 when full SSL inspection is active in the guest policy?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Refer to the exhibit, which shows a corporate network and a new remote office network.
An administrator must integrate the new remote office network with the corporate enterprise
network.
What must the administrator do to allow routing between the two networks?
An administrator must integrate the new remote office network with the corporate enterprise
network.
What must the administrator do to allow routing between the two networks?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
An administrator needs to install an IPS profile without triggering false positives that can impact
applications and cause problems with the user's normal traffic flow.
Which action can the administrator take to prevent false positives on IPS analysis?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
A company's users on an IPsec VPN between FortiGate A and B have experienced intermittent issues
since implementing VXLAN. The administrator suspects that packets exceeding the 1500-byte default
MTU are causing the problems.
In which situation would adjusting the interface’s maximum MTU value help resolve issues caused by
protocols that add extra headers to IP packets?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Refer to the exhibit, which shows an enterprise network connected to an internet service provider.
The administrator must configure the BGP section of FortiGate A to give internet access to the
enterprise network.
Which command must the administrator use to establish a connection with the internet service
provider?
The administrator must configure the BGP section of FortiGate A to give internet access to the
enterprise network.
Which command must the administrator use to establish a connection with the internet service
provider?Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2