Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE7_EFW-7.0 topic 1 question 8 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 8
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Refer to the exhibit, which contains the partial output of the get vpn ipsec tunnel details command.

Based on the output, which two statements are correct? (Choose two.)

  • A. The npu_flag for this tunnel is 03.
  • B. Different SPI values are a result of auto-negotiation being disabled for phase 2 selectors.
  • C. Anti-replay is enabled.
  • D. The npu_flag for this tunnel is 02.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
johnnd
Highly Voted 1 year ago
Selected Answer: AC
npu_flag=00 Both IPsec SAs loaded to the kernel npu_flag=01 Outbound IPsec SA copied to NPU npu_flag=02 Inbound IPsec SA copied to NPN npu_flag=03 Both outbound and inbound IPsec SA copied to NPU npu_flag=20 Unsupported cipher or HMAC, IPsec SA cannot be offloaded
upvoted 13 times
...
romartinedg
Most Recent 8 months, 1 week ago
A,C son correctas
upvoted 1 times
...
nerrabacer
8 months, 1 week ago
screenshot is the correct?
upvoted 1 times
...
certifi46
12 months ago
Selected Answer: AC
npu_flag=03 Both outbound and inbound IPsec SA copied to NPU "set replay enable" under config vpn ipsec phase2-interface in order to enable Anti-Replay
upvoted 3 times
mau_80
10 months, 3 weeks ago
Is the "set replay enable" screenshot missing?
upvoted 1 times
...
...
Quetchup
1 year, 1 month ago
Selected Answer: AC
Enterprise_Firewall_7.0_Study_Guide-Online.pdf p 444, 445, 449
upvoted 2 times
...
Beluga123
1 year, 2 months ago
A - npu_flag=03 Means that both ingress & egress ESP packets will be offloaded. C - "set replay enable" under config vpn ipsec phase2-interface in order to enable Anti-Replay
upvoted 2 times
...
Seph1
1 year, 3 months ago
A and C are correct
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...