Mastering IBGP Neighbor Groups and Route Reflectors in a Hub and Spoke Network
30 Questions
1 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which routing protocols are supported by AD-VPN?

  • BGP, OSPF, RIP, PIM
  • BGP, OSPF, EIGRP, IS-IS
  • BGP, EIGRP, IS-IS, PIM
  • BGP, OSPF, Ripv2, Rip next-generation (correct)
  • What type of IP addresses are supported by AD-VPN?

  • Only IP-v4
  • Only IP-v6
  • Neither IP-v4 nor IP-v6
  • Both IP-v4 and IP-v6 (correct)
  • What is required for the on-demand tunnels in AD-VPN?

  • NAT (correct)
  • PIM/multicast
  • Static routing
  • Dynamic routing
  • What type of architecture does AD-VPN support?

    <p>Single or multiple hub architectures</p> Signup and view all the answers

    What is the purpose of negotiation in AD-VPN?

    <p>To establish a connection attempt</p> Signup and view all the answers

    What is the role of Boston in the negotiation process?

    <p>To receive a connection attempt from London</p> Signup and view all the answers

    What type of architecture does AD-VPN support?

    <p>Hub-and-spoke</p> Signup and view all the answers

    What is the purpose of NAT in AD-VPN?

    <p>To support on-demand tunnels</p> Signup and view all the answers

    What type of traffic does AD-VPN support?

    <p>PIM/multicast</p> Signup and view all the answers

    What is required for AD-VPN to function?

    <p>Use of dynamic routing</p> Signup and view all the answers

    Which routing protocol is required for AD-VPN?

    <p>BGP</p> Signup and view all the answers

    What is the purpose of the overlay subnet in a hub-and-spoke topology?

    <p>To provide a unique IP address for each participant</p> Signup and view all the answers

    What is the purpose of the shortcut offer message in the AD-VPN negotiation process?

    <p>To notify the hub of available tunnel options</p> Signup and view all the answers

    What information does Boston include in the IKE message when negotiating a direct connection to London?

    <p>Boston's public IP-address and desired destination subnet</p> Signup and view all the answers

    How does Hub 1 know that AD-VPN is enabled in all the VPNs all the way to London?

    <p>Through auto-discovery-sender enable settings</p> Signup and view all the answers

    What is the purpose of the phase-2 configuration in AD-VPN?

    <p>To set the quick modes for the VPN</p> Signup and view all the answers

    How does Spoke-1 acknowledge the shortcut offer from the Hub?

    <p>By sending a shortcut query to the Hub</p> Signup and view all the answers

    What does Hub 2 have in this example of AD-VPN topology?

    <p>Two spokes</p> Signup and view all the answers

    What happens when Hub 1 receives packets from Boston destined for London?

    <p>Hub 1 sends an IKE message to Boston</p> Signup and view all the answers

    What initiates the tunnel IKE negotiation between Spoke-1 and Spoke-2?

    <p>The firewall policy</p> Signup and view all the answers

    Which command should be used to enable AD-VPN in a spoke?

    <p>auto-discovery-receiver</p> Signup and view all the answers

    What must be configured in the hub to enable AD-VPN for IPsec traffic?

    <p>auto-discovery-sender</p> Signup and view all the answers

    What is the purpose of configuring a BGP neighbor group in the hub?

    <p>To forward routes learned from one spoke to other spokes</p> Signup and view all the answers

    What should be done in the hub to ensure dynamic routing is used for learning the spokes' protected subnets?

    <p>Disable set add-route</p> Signup and view all the answers

    What is the requirement for having a dynamic routing protocol over IPsec?

    <p>Assign an overlay IP-address to the IPsec virtual interface</p> Signup and view all the answers

    What command should be used to indicate that an IPsec tunnel wants to participate in an auto-discovery VPN?

    <p>auto-discovery-receiver</p> Signup and view all the answers

    What should be included in the neighbor range configuration in the hub?

    <p>All the spokes individually as neighbors</p> Signup and view all the answers

    What should be done to ensure FortiGate does not create a dynamic interface in the hub?

    <p>Disable set net-device</p> Signup and view all the answers

    What should be added to BGP configuration in the hub to advertise the local network(s) behind the hub over BGP?

    <p>set add-route</p> Signup and view all the answers

    What should be assigned to the IPsec virtual interface in a spoke?

    <p>Interface IP</p> Signup and view all the answers

    More Like This

    Mastering Hub Device Routing in AD-VPN
    20 questions
    SD-WAN and AD-VPN Deployment Basics Quiz
    20 questions
    AD-VPN
    30 questions

    AD-VPN

    VisionarySugilite avatar
    VisionarySugilite
    Ad-Dukhan
    5 questions
    Use Quizgecko on...
    Browser
    Browser