Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE8_812 Topic 1 Question 22 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 22
Topic #: 1
[All NSE8_812 Questions]

An HA topology is using the following configuration:

Based on this configuration, how long will it take for a failover to be detected by the secondary cluster member?

Show Suggested Answer Hide Answer
Suggested Answer: B, D, E

Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.

Dmust be set to enable add-route, which is the command that actually injects the IKE routes.

Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.

The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.

References:

Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0

Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0


Contribute your Thoughts:

Carey
1 days ago
Hmm, I think the answer is C) 300ms. That delay seems like a reasonable time for the secondary cluster member to detect a failover.
upvoted 0 times
...
Chaya
5 days ago
I'm confident in my answer because the configuration shows a longer detection time.
upvoted 0 times
...
Kendra
7 days ago
I disagree, I believe it's B) 200ms.
upvoted 0 times
...
Chaya
10 days ago
I think the answer is A) 600ms.
upvoted 0 times
...

Save Cancel