Valid NSE7_EFW-7.2 Dumps shared by ExamDiscuss.com for Helping Passing NSE7_EFW-7.2 Exam! ExamDiscuss.com now offer the newest NSE7_EFW-7.2 exam dumps, the ExamDiscuss.com NSE7_EFW-7.2 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com NSE7_EFW-7.2 dumps with Test Engine here:
Exhibit. Refer to the exhibit, which shows a partial touting table What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)
Correct Answer: B,D
* Option B is correct because the routing table shows that the tunnel interfaces have a netmask of 255.255.255.255, which indicates that net-device is enabled in the phase 1 configuration. This option allows the FortiGate to use the tunnel interface as a next-hop for routing, without adding a route to the phase 2 destination1. * Option D is correct because the routing table does not show any routes to the phase 2 destination networks, which indicates that add-route is disabled in the phase 1 configuration. This option controls whether the FortiGate adds a static route to the phase 2 destination network using the tunnel interface as the gateway2. * Option A is incorrect because IPSec tunnel aggregation is a feature that allows multiple phase 2 selectors to share a single phase 1 tunnel, reducing the number of tunnels and improving performance3. This feature is not related to the routing table or the phase 1 configuration. * Option C is incorrect because OSPF is a dynamic routing protocol that can run over IPSec tunnels, but it requires additional configuration on the FortiGate and the peer device4. This option is not related to the routing table or the phase 1 configuration. References: = * 1: Technical Tip: 'set net-device' new route-based IPsec logic2 * 2: Adding a static route5 * 3: IPSec VPN concepts6 * 4: Dynamic routing over IPsec VPN7