Test Your Knowledge of IPsec Configuration for SD-WAN Overlays
30 Questions
1 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which interface is the tunnel bound to for the dial-up ISP1 overlays?

  • port4
  • port2
  • port1 (correct)
  • port3
  • What is the mode config address range for the dial-up ISP2 overlays?

  • 10.201.1.0/24
  • 10.204.1.0/24
  • 10.202.1.0/24 (correct)
  • 10.203.1.0/24
  • What is the type of the tunnel set to for the dial-up ISP1 overlays?

  • dynamic (correct)
  • static
  • manual
  • hybrid
  • Which version of IKE is often preferred for SD-WAN?

    <p>IKE-v2</p> Signup and view all the answers

    What is the purpose of disabling the 'net-device' setting?

    <p>To improve performance on large deployments</p> Signup and view all the answers

    What is the recommended mode for dead peer detection on dial-up servers?

    <p>On-demand</p> Signup and view all the answers

    What is the purpose of enabling 'mode-cfg'?

    <p>To assign IP-addresses to overlays on spokes</p> Signup and view all the answers

    What is the binding interface for the dial-up ISP2 overlays?

    <p>port2</p> Signup and view all the answers

    What is the purpose of disabling the 'add-route' setting?

    <p>To exchange routing information through the tunnels</p> Signup and view all the answers

    What is the recommended mode for hubs to scale better?

    <p>Passive</p> Signup and view all the answers

    Which protocol is used for exchanging prefixes in the SD-WAN overlay design?

    <p>BGP</p> Signup and view all the answers

    What is the purpose of the loopback interface in the SD-WAN overlay design?

    <p>To act as the target server for performance SLAs</p> Signup and view all the answers

    Why is it necessary to disable net-device in the phase1 configuration of IPsec tunnels in the SD-WAN overlay design?

    <p>To allow BGP peerings</p> Signup and view all the answers

    What is the benefit of using passive monitoring in the SD-WAN overlay design?

    <p>Reduced administrative overhead</p> Signup and view all the answers

    What is the advantage of using route tags instead of fixed firewall address objects in the SD-WAN overlay design?

    <p>Easier configuration changes</p> Signup and view all the answers

    Why is IBGP preferred over EBGP in the SD-WAN overlay design?

    <p>It preserves the next hop for prefixes</p> Signup and view all the answers

    What must be enabled to support Equal Cost Multipath (ECMP) for IBGP routes in the SD-WAN overlay design?

    <p>ibgp-multipath</p> Signup and view all the answers

    What is the purpose of the route-reflector-client setting in the SD-WAN overlay design?

    <p>To act as a route reflector</p> Signup and view all the answers

    Why is the update-source setting configured in the BGP configuration of the SD-WAN overlay design?

    <p>To ensure consistency in source IP addresses</p> Signup and view all the answers

    What does the BGP route reflector do in the SD-WAN overlay design?

    <p>Reflect learned routes from a spoke to other spokes</p> Signup and view all the answers

    Which overlay does the hub use to learn the 10.0.1.0/24 prefix?

    <p>T_INET_0</p> Signup and view all the answers

    What are the next hop IP addresses for the hub to learn the 10.0.1.0/24 prefix?

    <p>10.201.1.1 and 10.202.1.1</p> Signup and view all the answers

    What does spoke2 perform to determine the outgoing interface for the prefixes?

    <p>Recursive lookup</p> Signup and view all the answers

    Why are there two duplicate routes for the 10.0.1.0/24 prefix in the routing table of spoke2?

    <p>IBGP preserves the next hop</p> Signup and view all the answers

    What is the reason for the hub not reflecting the path through 10.202.1.1?

    <p>The hub is not configured to advertise additional paths</p> Signup and view all the answers

    What is the purpose of the neighbor-range entry in the IBGP configuration?

    <p>Defines the IP-address range for each neighbor group</p> Signup and view all the answers

    What does the config network entry in the IBGP configuration indicate?

    <p>The interior gateway protocol and prefix to inject into the BGP table</p> Signup and view all the answers

    Why is the network entry for 10.1.0.0/24 included in the IBGP configuration?

    <p>To advertise the connected route to the spokes</p> Signup and view all the answers

    What does IGP refer to in the context of the hub routing table?

    <p>Non-BGP routes such as OSPF, Rip, connected, and static</p> Signup and view all the answers

    Starting from which FortiOS versions are duplicate routes consolidated in the routing table output?

    <p>6.4.7 and 7.0.1</p> Signup and view all the answers

    More Like This

    SD-WAN
    20 questions

    SD-WAN

    VisionarySugilite avatar
    VisionarySugilite
    Forward Traffic Logs in SD-WAN
    20 questions
    SD-WAN Session Management Quiz
    20 questions
    Use Quizgecko on...
    Browser
    Browser