Podcast
Questions and Answers
Which routing protocols are supported by AD-VPN?
Which routing protocols are supported by AD-VPN?
What type of IP addresses are supported by AD-VPN?
What type of IP addresses are supported by AD-VPN?
What is required for the on-demand tunnels in AD-VPN?
What is required for the on-demand tunnels in AD-VPN?
What type of architecture does AD-VPN support?
What type of architecture does AD-VPN support?
Signup and view all the answers
What is the purpose of negotiation in AD-VPN?
What is the purpose of negotiation in AD-VPN?
Signup and view all the answers
What is the role of Boston in the negotiation process?
What is the role of Boston in the negotiation process?
Signup and view all the answers
What type of architecture does AD-VPN support?
What type of architecture does AD-VPN support?
Signup and view all the answers
What is the purpose of NAT in AD-VPN?
What is the purpose of NAT in AD-VPN?
Signup and view all the answers
What type of traffic does AD-VPN support?
What type of traffic does AD-VPN support?
Signup and view all the answers
What is required for AD-VPN to function?
What is required for AD-VPN to function?
Signup and view all the answers
Which routing protocol is required for AD-VPN?
Which routing protocol is required for AD-VPN?
Signup and view all the answers
What is the purpose of the overlay subnet in a hub-and-spoke topology?
What is the purpose of the overlay subnet in a hub-and-spoke topology?
Signup and view all the answers
What is the purpose of the shortcut offer message in the AD-VPN negotiation process?
What is the purpose of the shortcut offer message in the AD-VPN negotiation process?
Signup and view all the answers
What information does Boston include in the IKE message when negotiating a direct connection to London?
What information does Boston include in the IKE message when negotiating a direct connection to London?
Signup and view all the answers
How does Hub 1 know that AD-VPN is enabled in all the VPNs all the way to London?
How does Hub 1 know that AD-VPN is enabled in all the VPNs all the way to London?
Signup and view all the answers
What is the purpose of the phase-2 configuration in AD-VPN?
What is the purpose of the phase-2 configuration in AD-VPN?
Signup and view all the answers
How does Spoke-1 acknowledge the shortcut offer from the Hub?
How does Spoke-1 acknowledge the shortcut offer from the Hub?
Signup and view all the answers
What does Hub 2 have in this example of AD-VPN topology?
What does Hub 2 have in this example of AD-VPN topology?
Signup and view all the answers
What happens when Hub 1 receives packets from Boston destined for London?
What happens when Hub 1 receives packets from Boston destined for London?
Signup and view all the answers
What initiates the tunnel IKE negotiation between Spoke-1 and Spoke-2?
What initiates the tunnel IKE negotiation between Spoke-1 and Spoke-2?
Signup and view all the answers
Which command should be used to enable AD-VPN in a spoke?
Which command should be used to enable AD-VPN in a spoke?
Signup and view all the answers
What must be configured in the hub to enable AD-VPN for IPsec traffic?
What must be configured in the hub to enable AD-VPN for IPsec traffic?
Signup and view all the answers
What is the purpose of configuring a BGP neighbor group in the hub?
What is the purpose of configuring a BGP neighbor group in the hub?
Signup and view all the answers
What should be done in the hub to ensure dynamic routing is used for learning the spokes' protected subnets?
What should be done in the hub to ensure dynamic routing is used for learning the spokes' protected subnets?
Signup and view all the answers
What is the requirement for having a dynamic routing protocol over IPsec?
What is the requirement for having a dynamic routing protocol over IPsec?
Signup and view all the answers
What command should be used to indicate that an IPsec tunnel wants to participate in an auto-discovery VPN?
What command should be used to indicate that an IPsec tunnel wants to participate in an auto-discovery VPN?
Signup and view all the answers
What should be included in the neighbor range configuration in the hub?
What should be included in the neighbor range configuration in the hub?
Signup and view all the answers
What should be done to ensure FortiGate does not create a dynamic interface in the hub?
What should be done to ensure FortiGate does not create a dynamic interface in the hub?
Signup and view all the answers
What should be added to BGP configuration in the hub to advertise the local network(s) behind the hub over BGP?
What should be added to BGP configuration in the hub to advertise the local network(s) behind the hub over BGP?
Signup and view all the answers
What should be assigned to the IPsec virtual interface in a spoke?
What should be assigned to the IPsec virtual interface in a spoke?
Signup and view all the answers