Test Your Knowledge of IPsec Configuration for SD-WAN Overlays

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to Lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which interface is the tunnel bound to for the dial-up ISP1 overlays?

  • port4
  • port2
  • port1 (correct)
  • port3

What is the mode config address range for the dial-up ISP2 overlays?

  • 10.201.1.0/24
  • 10.204.1.0/24
  • 10.202.1.0/24 (correct)
  • 10.203.1.0/24

What is the type of the tunnel set to for the dial-up ISP1 overlays?

  • dynamic (correct)
  • static
  • manual
  • hybrid

Which version of IKE is often preferred for SD-WAN?

<p>IKE-v2 (B)</p> Signup and view all the answers

What is the purpose of disabling the 'net-device' setting?

<p>To improve performance on large deployments (C)</p> Signup and view all the answers

What is the recommended mode for dead peer detection on dial-up servers?

<p>On-demand (A)</p> Signup and view all the answers

What is the purpose of enabling 'mode-cfg'?

<p>To assign IP-addresses to overlays on spokes (B)</p> Signup and view all the answers

What is the binding interface for the dial-up ISP2 overlays?

<p>port2 (C)</p> Signup and view all the answers

What is the purpose of disabling the 'add-route' setting?

<p>To exchange routing information through the tunnels (B)</p> Signup and view all the answers

What is the recommended mode for hubs to scale better?

<p>Passive (C)</p> Signup and view all the answers

Which protocol is used for exchanging prefixes in the SD-WAN overlay design?

<p>BGP (D)</p> Signup and view all the answers

What is the purpose of the loopback interface in the SD-WAN overlay design?

<p>To act as the target server for performance SLAs (A)</p> Signup and view all the answers

Why is it necessary to disable net-device in the phase1 configuration of IPsec tunnels in the SD-WAN overlay design?

<p>To allow BGP peerings (A)</p> Signup and view all the answers

What is the benefit of using passive monitoring in the SD-WAN overlay design?

<p>Reduced administrative overhead (C)</p> Signup and view all the answers

What is the advantage of using route tags instead of fixed firewall address objects in the SD-WAN overlay design?

<p>Easier configuration changes (C)</p> Signup and view all the answers

Why is IBGP preferred over EBGP in the SD-WAN overlay design?

<p>It preserves the next hop for prefixes (D)</p> Signup and view all the answers

What must be enabled to support Equal Cost Multipath (ECMP) for IBGP routes in the SD-WAN overlay design?

<p>ibgp-multipath (D)</p> Signup and view all the answers

What is the purpose of the route-reflector-client setting in the SD-WAN overlay design?

<p>To act as a route reflector (B)</p> Signup and view all the answers

Why is the update-source setting configured in the BGP configuration of the SD-WAN overlay design?

<p>To ensure consistency in source IP addresses (A)</p> Signup and view all the answers

What does the BGP route reflector do in the SD-WAN overlay design?

<p>Reflect learned routes from a spoke to other spokes (C)</p> Signup and view all the answers

Which overlay does the hub use to learn the 10.0.1.0/24 prefix?

<p>T_INET_0 (C)</p> Signup and view all the answers

What are the next hop IP addresses for the hub to learn the 10.0.1.0/24 prefix?

<p>10.201.1.1 and 10.202.1.1 (C)</p> Signup and view all the answers

What does spoke2 perform to determine the outgoing interface for the prefixes?

<p>Recursive lookup (C)</p> Signup and view all the answers

Why are there two duplicate routes for the 10.0.1.0/24 prefix in the routing table of spoke2?

<p>IBGP preserves the next hop (C)</p> Signup and view all the answers

What is the reason for the hub not reflecting the path through 10.202.1.1?

<p>The hub is not configured to advertise additional paths (A)</p> Signup and view all the answers

What is the purpose of the neighbor-range entry in the IBGP configuration?

<p>Defines the IP-address range for each neighbor group (A)</p> Signup and view all the answers

What does the config network entry in the IBGP configuration indicate?

<p>The interior gateway protocol and prefix to inject into the BGP table (B)</p> Signup and view all the answers

Why is the network entry for 10.1.0.0/24 included in the IBGP configuration?

<p>To advertise the connected route to the spokes (D)</p> Signup and view all the answers

What does IGP refer to in the context of the hub routing table?

<p>Non-BGP routes such as OSPF, Rip, connected, and static (D)</p> Signup and view all the answers

Starting from which FortiOS versions are duplicate routes consolidated in the routing table output?

<p>6.4.7 and 7.0.1 (D)</p> Signup and view all the answers

Flashcards are hidden until you start studying

More Like This

SD-WAN
20 questions

SD-WAN

VisionarySugilite avatar
VisionarySugilite
Forward Traffic Logs in SD-WAN
20 questions
SD-WAN Session Management Quiz
20 questions
SD-WAN Features and Capabilities Quiz
18 questions
Use Quizgecko on...
Browser
Browser