Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam FCSS_EFW_AD-7.4 Topic 5 Question 5 Discussion

Actual exam question for Fortinet's FCSS_EFW_AD-7.4 exam
Question #: 5
Topic #: 5
[All FCSS_EFW_AD-7.4 Questions]

Refer to the exhibit, which shows a network diagram showing the addition of site 2 with an overlapping network segment to the existing VPN IPsec connection between the hub and site 1.

Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?

Show Suggested Answer Hide Answer
Suggested Answer: A

When multiple remote sites connect to the same hub using overlapping subnets, FortiGate needs to determine which route should be used for traffic forwarding. The route-overlap setting in IPsec Phase 2 allows FortiGate to handle this scenario by deciding whether to keep the existing route (use-old) or replace it with a new route (use-new).

In an ECMP (Equal-Cost Multi-Path) routing setup, both routes should be retained and balanced, but FortiGate does not support ECMP directly over overlapping routes in IPsec Phase 2. Instead, an administrator must decide which connection takes precedence using route-overlap settings.


Contribute your Thoughts:

Bobbye
1 days ago
I'm going with Option D. The 'allow' setting for route-overlap seems like the appropriate configuration to handle the overlapping subnets.
upvoted 0 times
...
Sommer
2 days ago
Option B seems the most logical choice here. Setting net-device to ecmp should enable ECMP routing for the overlapping subnets.
upvoted 0 times
...
Tracey
2 days ago
I agree with Nadine, because setting route-overlap to either use-new or use-old would enable ECMP routing.
upvoted 0 times
...
Nadine
6 days ago
I think the answer is A) Set route-overlap to either use-new or use-old.
upvoted 0 times
...

Save Cancel