Auto discovery VPN
Active Directory VPN
Active Direct VPN
Which VPN topology does not allow direct communication between spokes?
a. Partial mesh
Which VPN topology is the most fault tolerant?
a. Full mesh
FortiGate operation mode: NAT and transparent
Routing protocols: No
Number of policies per VPN: One policy controls both traffic directions
FortiGate operation mode: Only NAT
Routing protocols: Yes
Number of policies per VPN: Two policies (usually)—one for each direction
Transparent mode supports only policy-based VPNs
Generally, try to use policy-based because it offers more ﬂexibility and control.
Trafﬁc must be routed to the lPsec virtual network interface.
Usually two firewall policies with the Action set to ACCEPT are required (one per direction).
One ﬁrewall policy with the Action set to lPsec is required.
By default, hidden on the GUI. To show.
Wizard vpn creates only route-based VPNs
SD-WAN feature can also be used for VPN redundancy.
Add one phase 1 configuration for each tunnel. Dead peer detection (DPD) must be enabled on both ends.
Add at least one phase 2 definition for each phase 1.
Add one static route for each path. Use distance or priority to select primary routes over backup routes. Alternatively, use dynamic routing.
Conﬁgure firewall policies for each lPsec interface.
When configuring policy-based VPN, what option do you need to select for the Action setting?
Which of the following statements about route-based VPN is correct?
a. It usually requires two firewall policies—one for each direction.
b. One policy controls both traffic directions.
diagnose vpn tunnel list - command to verify if traffic is offloaded.
Keeping a real-time debug running on the background of a FortiGate for a long time it is necessary some times.
ipsec vpn policy-based debug
ipsec vpn routed-based debug
Which one of the following messages indicates that both ingress and egress ESP packets will be offloaded?
If you enable NAT in the firewall policy for VPN, which of the following issues may occur?
a. Quick mode selector may mismatch
b. Trafﬁc may not be routed to the tunnel