Master VPN Topologies
30 Questions
1 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which type of VPN topology is shown in the example on this slide?

  • Hub-and-spoke (correct)
  • Full mesh
  • Partial mesh
  • AD-VPN
  • What is a disadvantage of using a hub-and-spoke VPN topology?

  • Fast communication between branch offices
  • Limited system requirements for branch offices
  • Minimal planning required for routing
  • Lack of redundancy (correct)
  • In a hub-and-spoke VPN topology, where does the traffic between branch offices flow through?

  • Firewall
  • ISP
  • Direct connection between branch offices
  • Hub (correct)
  • Which type of mesh topology attempts to minimize required resources and latency?

    <p>Partial mesh</p> Signup and view all the answers

    What is a benefit of using AD-VPN?

    <p>Direct connectivity between branch offices</p> Signup and view all the answers

    What does AD-VPN stand for?

    <p>Advanced Dynamic VPN</p> Signup and view all the answers

    What is a disadvantage of using a partial mesh topology?

    <p>Complex FortiGate device configurations</p> Signup and view all the answers

    What is the purpose of using a full mesh topology?

    <p>To establish communication between every location</p> Signup and view all the answers

    What can be a significant issue when using a hub-and-spoke VPN topology for global companies?

    <p>Physical distance</p> Signup and view all the answers

    What should you use to troubleshoot IPsec problems if the tunnel is unstable?

    <p>DPD packets</p> Signup and view all the answers

    Which type of topology is shown in the slide?

    <p>Full mesh</p> Signup and view all the answers

    How many VPN tunnels are needed for each FortiGate device in a full mesh topology?

    <p>4</p> Signup and view all the answers

    If a company has six locations, how many tunnels would be needed in a full mesh topology?

    <p>15</p> Signup and view all the answers

    What is the benefit of AD-VPN?

    <p>Direct connectivity between all sites</p> Signup and view all the answers

    What is the disadvantage of a full mesh topology?

    <p>Spoke FortiGate devices must be more powerful</p> Signup and view all the answers

    What is the formula to calculate the number of tunnels in a full mesh topology?

    <p>N sites = N (N-1) / 2</p> Signup and view all the answers

    Which topology places less strain on the central location?

    <p>Full mesh</p> Signup and view all the answers

    What is the main advantage of a hub-and-spoke topology?

    <p>Cheaper for many locations</p> Signup and view all the answers

    What is AD-VPN based on?

    <p>IKE and IPsec</p> Signup and view all the answers

    What version of FortiOS introduced AD-VPN?

    <p>5.4</p> Signup and view all the answers

    Which field in the FortiGate session table indicates the offloading status of IPsec SAs?

    <p>npu_flag</p> Signup and view all the answers

    When are the IPsec SAs copied to the NPU?

    <p>When the first IPsec packet arrives</p> Signup and view all the answers

    What does an npu_flag value of 00 indicate?

    <p>No traffic crossing the tunnel</p> Signup and view all the answers

    What does an npu_flag value of 01 indicate?

    <p>Outbound SA copied to NPU</p> Signup and view all the answers

    What does an npu_flag value of 02 indicate?

    <p>Inbound SA copied to NPU</p> Signup and view all the answers

    What does an npu_flag value of 03 indicate?

    <p>Both outbound and inbound SA copied to NPU</p> Signup and view all the answers

    What does an npu_flag value of 20 indicate?

    <p>Unsupported cipher or HMAC algorithm</p> Signup and view all the answers

    What does the npu_flag field indicate in the FortiGate session table?

    <p>Offloading status of IPsec SAs</p> Signup and view all the answers

    When are the IPsec SAs loaded to the kernel?

    <p>When phase-2 goes up</p> Signup and view all the answers

    What does an npu_flag value of 00 indicate when IPsec offloading is disabled?

    <p>No traffic crossing the tunnel</p> Signup and view all the answers

    More Like This

    VPN Gateways
    20 questions

    VPN Gateways

    VisionarySugilite avatar
    VisionarySugilite
    VPN Basics for Network Communication
    30 questions
    Use Quizgecko on...
    Browser
    Browser