View all questions & answers for the NSE 7 - Enterprise Firewall 7.6 Administrator Exam Materials exam
Question 16 Discussion
Comments
Selected Answers: B
FortiGate supports three DPD modes: on-demand, on-idle, and disable.
-> On-demand mode is best for environments where traffic patterns are unpredictable, and immediate response to connectivity issues is crucial.
-> On-idle mode is best for networks with regular traffic intervals, providing a balance between connectivity assurance and resource utilization.
-> Disable mode is suitable in highly stable environments where DPD overhead is unwarranted
D is wrong because certificate authentication in IKE uses local certificate and peer certificate, so we don't associate peer certificate with peer ID. Peer ID is not configurable in IKEv2 as in IKEv2 we can only use "set peertype any"
Selected Answers: B
Refer to the exhibit. A partial VPN configuration is shown. Which statement about this VPN IPsec phase 1 configuration is correct? (Choose one answer)
Brave-Dump Clients Votes