exam questions

Exam NSE8_812 All Questions

View all questions & answers for the NSE8_812 exam

Exam NSE8_812 topic 1 question 8 discussion

Actual exam question from Fortinet's NSE8_812
Question #: 8
Topic #: 1
[All NSE8_812 Questions]

Refer to the exhibits.

Exhibit A -


Exhibit B -


Exhibit C -

A customer is trying to set up a VPN with a FortiGate, but they do not have a backup of the configuration. Output during a troubleshooting session is shown in the exhibits A and B and a baseline VPN configuration is shown in Exhibit C.
Referring to the exhibits, which configuration will restore VPN connectivity?

  • A.
  • B.
  • C.
  • D.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Noidea
Highly Voted 1 year, 5 months ago
NPU_flag 03 both ingress and egress will be offloaded
upvoted 6 times
...
kinge2
Most Recent 4 months, 2 weeks ago
Selected Answer: D
NPU off load does not restore connectivity, other than accelrating VPN, It only allow viewing of logs
upvoted 1 times
...
dspavvn
8 months ago
It is more likely to be B as the peer ID in exhibit A states CN = gftdc01.example.com with peer-id-auth: yes, so it requires this specific peer ID, and in A, C, D the peer ID is "vpn-hub02-1_peer", which means the peer ID will be wrong. A cannot be because its IKEv1. C has disabled offloading, which does not affect the tunnel status but is not the same as the exhibit B, so cannot be correct based on that. D has everything correct, but using digital signature for auth, cannot verify this on any of the outputs and as the default auth-method is PSK, and they do not have a config backup, so no certificate to use if it was the case, makes D wrong too. B, based on the above, and the default for PSK setting for peer-id is accept all, is the only plausible option.
upvoted 1 times
...
node345
10 months, 3 weeks ago
Selected Answer: D
npu_flag=03. D is correct
upvoted 1 times
...
pitz
1 year, 3 months ago
Selected Answer: C
The output in Exhibit A shows that the VPN tunnel is not established because the peer IP address is incorrect. The output in Exhibit B shows that the peer IP address is 192.168.1.100, but the baseline VPN configuration in Exhibit C shows that the peer IP address should be 192.168.1.101. To restore VPN connectivity, you need to change the peer IP address in the VPN tunnel configuration to 192.168.1.101. The correct configuration is shown below: config vpn ipsec phase1-interface edit "wan" set peer-ip 192.168.1.101 set peer-id 192.168.1.101 set dhgrp 1 set auth-mode psk set psk SECRET_PSK next end Option A is incorrect because it does not change the peer IP address. Option B is incorrect because it changes the peer IP address to 192.168.1.100, which is the incorrect IP address. Option D is incorrect because it does not include the necessary configuration for the VPN tunnel
upvoted 1 times
ac89l
11 months, 4 weeks ago
my man, where do you see those addresses?
upvoted 1 times
...
...
ama6
1 year, 4 months ago
Correct answer is C
upvoted 1 times
...
pplee_sh
1 year, 4 months ago
Selected Answer: D
NPU_Flag 03
upvoted 3 times
...
Viewable8041
1 year, 4 months ago
Selected Answer: D
As Noidea and pwatchpk
upvoted 3 times
...
semsemccie
1 year, 5 months ago
Selected Answer: C
Correct answer is C
upvoted 1 times
...
pwatchpk
1 year, 5 months ago
D is correct
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago