exam questions

Exam NSE7_EFW-7.2 All Questions

View all questions & answers for the NSE7_EFW-7.2 exam

Exam NSE7_EFW-7.2 topic 1 question 33 discussion

Actual exam question from Fortinet's NSE7_EFW-7.2
Question #: 33
Topic #: 1
[All NSE7_EFW-7.2 Questions]

Which two statements about ADVPN are true? (Choose two.)

  • A. The hub adds routes based on IKE negotiations.
  • B. You must configure phase 2 quick mode selectors to 0.0.0.0 0.0.0.0.
  • C. All FortiGate devices must be in the same autonomous system (AS).
  • D. You must disable add-route in the hub.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
myrmidon3
4 months ago
Selected Answer: BD
A. You must disable add-route in the hub. True. For ADVPN (Auto-Discovery VPN) to work, the hub should not add routes automatically. Disabling add-route ensures that route discovery is dynamic and based on the ADVPN mechanism rather than static route additions. B. All FortiGate devices must be in the same autonomous system (AS). False. ADVPN can operate across different AS numbers as long as the routing and VPN configurations are correct. It does not require all FortiGates to be in the same AS. C. The hub adds routes based on IKE negotiations. False. ADVPN uses dynamic routing protocols (e.g., BGP or OSPF) to exchange routes, not IKE negotiations. IKE is responsible for establishing the VPN tunnels, but routing is handled separately. D. You must configure phase 2 quick mode selectors to 0.0.0.0 0.0.0.0. True. To enable ADVPN's dynamic capabilities, phase 2 quick mode selectors are typically set to 0.0.0.0/0 for both source and destination. This ensures that the VPN tunnel can dynamically accommodate various subnets.
upvoted 1 times
...
sugar12
9 months, 1 week ago
Selected Answer: BD
A. wrong - not relevant B. Correct because C is wrong and D is correct C. wrong devices can be in the same or not the same AS depending your topology. Also you can use EBGP rather than IBGP. it is recommended to use IBGP but that doesnt mean you cant use only EBGP. So it is not mandatory to be in the same AS. D. ADVPN runs on dynamic routing so you must disable add-routes etc.. - Correct
upvoted 1 times
...
havokdu
11 months, 3 weeks ago
Selected Answer: BD
Refer to Study guide 334. AD-VPN supports EBGP for inter-region routing (dual regions - Dual HUB). So the correct answer is BD
upvoted 1 times
...
charruco
1 year ago
Selected Answer: BD
B and D are correct study guide p. 336
upvoted 2 times
...
truserud
1 year, 1 month ago
Selected Answer: BD
Correction of my last answer.
upvoted 1 times
...
truserud
1 year, 1 month ago
Selected Answer: CD
This is a difficult one, This documentation states that members of an ADVPN must use IBGP - https://community.fortinet.com/t5/FortiGate/Technical-Tip-ADVPN-with-BGP-as-the-routing-protocol/ta-p/192437 , and thus must be in the same AS as answer C states. The hub must also be configured with set add-route disable, so D is definitely correct. The Study Guide merely states that you have to check and confirm that phase2 selectors are set to 0.0.0.0/0, which is the default setting as stated here https://docs.fortinet.com/document/fortigate/7.2.4/cli-reference/373620/config-vpn-ipsec-phase2-interface (dst-subnet row in table). I belive if you HAD to set 0.0.0.0/0 the documentation would actually show that in every configuration example of ADVPN. Thus I am going to say that C and D are the correct answers, just to confuse everyone, because I am a bit confused my self.
upvoted 1 times
havokdu
11 months, 3 weeks ago
AD-VPN supports EBGP for inter-region routing (dual regions - Dual HUB). So the correct answer is BD
upvoted 1 times
...
...
ac89l
1 year, 1 month ago
Selected Answer: BD
and also C is correct
upvoted 1 times
...
5deee77
1 year, 2 months ago
Selected Answer: BD
study guide p. 336
upvoted 3 times
...
Artbrut
1 year, 2 months ago
Selected Answer: BD
It's B and D as per study guide p. 336
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago