exam questions

Exam NSE7_EFW-7.2 All Questions

View all questions & answers for the NSE7_EFW-7.2 exam

Exam NSE7_EFW-7.2 topic 1 question 8 discussion

Actual exam question from Fortinet's NSE7_EFW-7.2
Question #: 8
Topic #: 1
[All NSE7_EFW-7.2 Questions]

Which two statements about IKE version 2 fragmentation are true? (Choose two.)

  • A. Only some IKE version 2 packets are considered fragmentable
  • B. The reassembly timeout default value is 30 seconds
  • C. It is performed at the IP layer
  • D. The maximum number of IKE version 2 fragments is 128
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
networkconundrums1
4 months, 2 weeks ago
Maximum number of IKEv2 fragments = 64 (for reassembly) The Answer is A and C
upvoted 1 times
...
mecacig953
6 months ago
only one anwer is right . A study guide page 300
upvoted 2 times
...
havokdu
7 months ago
Selected Answer: AC
A: Only some IKEv2 packets are considered fragmentable: AUTH, CREATE_CHILD_SA, and some INFORMATIONAL. B: Reassembly timeout is 15 seconds, not 30 seconds. C: Check the question and the Study guide. IKEv2 fragmentation does happen in the IP layer, and IKEv2 fragmentation "SUPPORT" happens at the IKE layer instead of the IP layer. D: The maximum number of IKEv2 fragments is 64, not 128
upvoted 4 times
...
charruco
8 months, 1 week ago
Selected Answer: AC
A and C are correct
upvoted 2 times
...
truserud
9 months, 3 weeks ago
Selected Answer: AC
A and C are correct. See page 300 in the Enterprise Firewall 7.2 Study Guide: A: Only some IKEv2 packets are considered fragmentable: AUTH, CREATE_CHILD_SA, and some INFORMATIONAL. C: Page 299 in Study Guide: If fragmentation occurs at the IP layer, during the IKEv2 connection, it is possible that payload sizes may exceed the IP MTU and packets get fragmented. Now, on page 300, it is indeed stated that fragmentation is performed on the IKE-layer to solve the issues raised with Fragmentation on the IP-layer. This is supported on IKEv2 with IKEv2 fragmentation support: config vpn ipsec-phase1-$interface set ike-version 2 set fragmentation enable | disable set fragmentation-mtu $size Bottom line; somewhat tricky question, at least with regards to it requesting two answers, and i definitely isn't B or D.
upvoted 4 times
...
Kop01
9 months, 4 weeks ago
Selected Answer: AC
Answer should be A only, but it requires 2 answers so it's AC ... p300 : A correct : "Only some packets are considered fragmentable." C wrong : "With IKEv2 fragmentation support, the fragmentation occurs at the IKE layer instead of the IP layer." BUT if set fragmentation is set to disable, then answer C could be right .... BD wrong : "The maximum number of IKEv2 fragments are 64, and the reassembly timeout is 15 seconds."
upvoted 1 times
...
Artbrut
10 months ago
Selected Answer: A
only A is correct imho A -> yes, study guide p. 300 B -> reassembly timeout 15 sec, not 30 C -> nope, fragmentation is done at IKE layer, not IP! (To not be blocked by firewalls) D -> nope, the max number is 64 (p. 300 study guide)
upvoted 1 times
Artbrut
10 months ago
regarding C: it could be right if ikev2 fragmentation support is not configured
upvoted 1 times
...
...
5deee77
10 months ago
Selected Answer: AC
The answer is A (page 300) C (page 299) Enterprise_Firewall_7.2_Study_Guide
upvoted 1 times
...
rananaj
10 months, 1 week ago
Selected Answer: BC
The answer is BC
upvoted 1 times
rananaj
10 months, 1 week ago
The answer is AC
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago