Valid FCSS_LED_AR-7.6 Dumps shared by EduDump.com for Helping Passing FCSS_LED_AR-7.6 Exam! EduDump.com now offer the newest FCSS_LED_AR-7.6 exam dumps, the EduDump.com FCSS_LED_AR-7.6 exam questions have been updated and answers have been corrected get the newest EduDump.com FCSS_LED_AR-7.6 dumps with Test Engine here:
APs have been manually configured to connect to FortiGate over an IPsec network, and FortiGate successfully detects and authorizes them. However, the APs remain unmanaged because FortiGate is unable to establish a CAPWAP tunnel with them. What configuration change can resolve this issue and enable FortiGate to establish the CAPWAP tunnel over the IPsec connection?
Correct Answer: B
When FortiAPs connect to FortiGate overIPsec tunnels, this is treated similarly to WAN/MPLS deployments. In these scenarios, FortiGate must know that CAPWAP must traverse anon-L2transport. FortiAP profiles include: set mpls-connection enable This setting is required so that: * FortiGate can encapsulate CAPWAP inside the transport tunnel * Remote FortiAPs can establish CAPWAP even when behind routed/IPsec networks Without this option, the FortiGate detects the AP butcannot bring CAPWAP UP, leaving the AP in "discovered/unauthorized" or "offline" state. Why others are wrong * A. Static route# Discovery already succeeds, so routing is not the issue. * C. Reduce MTU# Sometimes useful for IPsec, but not required for CAPWAP establishment. * D. Firmware upgrade# Firmware mismatch would show "Managed (upgrade required)," not CAPWAP tunnel failure. Therefore,set mpls-connection enableis the required fix.