AD-VPN
30 Questions
0 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which protocol(s) does AD-VPN support for dynamic routing?

  • BGP, OSPF, Rip-v2 and Rip-NG (correct)
  • BGP only
  • OSPF only
  • Rip-v2 and Rip-NG only

What are the overlays that connect a spoke to a hub called?

  • Direct tunnels
  • Parent tunnels (correct)
  • Shortcut tunnels
  • Child tunnels

What are the direct tunnels negotiated over parent tunnels called?

  • Auto-discovery tunnels
  • Shortcut tunnels (correct)
  • Overlay tunnels
  • Dynamic tunnels

What should be enabled on the spoke overlay to inform the hubs that the spoke can negotiate shortcuts?

<p>Auto-discovery-receiver (C)</p> Signup and view all the answers

What should be enabled on the hub overlay that connects the spoke to allow for shortcut negotiation between spokes?

<p>Auto-discovery-sender (A)</p> Signup and view all the answers

What should be enabled on the hub overlay that connects to the other hub to forward AD-VPN sender and receiver information between hubs?

<p>Auto-discovery-forwarder (B)</p> Signup and view all the answers

What happens when a user in Boston sends traffic to London and the shortcut between them has not been negotiated?

<p>The traffic is routed through Hub1 and Hub2 (B)</p> Signup and view all the answers

What message does Hub1 send to Boston to inform that it can try to negotiate a direct connection to London?

<p>Shortcut offer message (D)</p> Signup and view all the answers

What message does Boston send to acknowledge the shortcut offer from Hub1?

<p>Shortcut query message (A)</p> Signup and view all the answers

What initiates the tunnel IKE negotiation between Spoke1 and Spoke2?

<p>Traffic from Spoke1 to Spoke2 (B)</p> Signup and view all the answers

Which configuration must be enabled on the phase1 of each overlay on spokes?

<p>net-device and auto-discovery-receiver (B)</p> Signup and view all the answers

What happens if ping access is not enabled on the interface of the spokes?

<p>Ping probes fail and shortcuts are marked as dead. (B)</p> Signup and view all the answers

Why is overlay stickiness important for AD-VPN?

<p>It prevents spokes from negotiating shortcuts over unreachable underlays. (A)</p> Signup and view all the answers

Which type of link is MPLS?

<p>Private link assigned with a private IP-address (B)</p> Signup and view all the answers

Why do cross-ISP overlays fail to establish?

<p>The ISP1 and MPLS networks are not routable between them. (B)</p> Signup and view all the answers

What must be changed from their default values in AD-VPN with FortiManager VPN Manager?

<p>Set protected networks to all (A)</p> Signup and view all the answers

What does disabling the Add Route option on the hub prevent?

<p>The hub from adding routes based on IKE negotiations (D)</p> Signup and view all the answers

What is the phase1 name created when using FortiManager VPN console for AD-VPN?

<p>Phase1name_0 (A)</p> Signup and view all the answers

Where is the configuration of the Protected Subnet located?

<p>VPN Communities (D)</p> Signup and view all the answers

What does AD-VPN use instead of adding routes based on IKE negotiations?

<p>Dynamic routing protocol (C)</p> Signup and view all the answers

Which technology enables direct spoke-to-spoke communication in a hub-and-spoke network?

<p>AD-VPN (C)</p> Signup and view all the answers

What is the basis of the AD-VPN solution?

<p>IKE and IPsec (B)</p> Signup and view all the answers

What are the benefits of using full-mesh topology in a hub-and-spoke network?

<p>Direct spoke-to-spoke communication (A)</p> Signup and view all the answers

What is the alternative to using a full-mesh topology in a hub-and-spoke network?

<p>AD-VPN (C)</p> Signup and view all the answers

What does SD-WAN support in relation to AD-VPN?

<p>AD-VPN shortcuts (A)</p> Signup and view all the answers

What increases the delay of communication in a hub-and-spoke topology?

<p>Communication through the hub (D)</p> Signup and view all the answers

What is the impact of geographically distant hub and spokes in a hub-and-spoke topology?

<p>Increased delay of communication (A)</p> Signup and view all the answers

What does AD-VPN enable spokes to do without making many configuration changes?

<p>Negotiate on-demand IPsec tunnels (B)</p> Signup and view all the answers

What does SD-WAN do with traffic in relation to AD-VPN shortcuts?

<p>Steers traffic through shortcuts (A)</p> Signup and view all the answers

What is the main advantage of using AD-VPN in a hub-and-spoke topology?

<p>Enables direct spoke-to-spoke communication (A)</p> Signup and view all the answers
Use Quizgecko on...
Browser
Browser