https://docs.fortinet.com/document/fortigate/7.2.0/new-features/661245/add-log-field-to-identify-advpn-shortcuts-in-vpn-logs
'A value of 1 indicates the tunnel is an ADVPN shortcut, and 0 indicates it is not'
I did not find anything in the text book referencing a "master tunnel" on page 283 it clearly states that a tunnel is assigned 1 for shortcut tunnel and 0 for normal tunnel. Therefore D is correct.
Explanation:
Line 8:The log entry shows an IPsec tunnel named "T_MPLS_0", with an advpnc=1.
This indicates that the tunnel T_MPLS_0 is being used as a master tunnel and has created a shortcut tunnel for ADVPN.
The presence of advpnc=1 confirms the shortcut tunnel.
Why not the other options?
B. The master tunnel T_INET_0 cannot accept the ADVPN shortcut.
Incorrect. The logs do not indicate that T_INET_0 is incapable of ADVPN shortcuts. The advpnc=0 simply means no shortcut was created for that particular tunnel.
C. There are no IPsec tunnel statistics log messages for ADVPN shortcuts.
Incorrect. The log entry for T_MPLS_0 clearly shows an advpnc=1, confirming the presence of an ADVPN shortcut.
D. The VPN tunnel T_MPLS_0 is a shortcut tunnel.
Incorrect. T_MPLS_0 is a master tunnel, and a shortcut tunnel is built from it.
Thus, A is the correct answer because there is one shortcut tunnel built from T_MPLS_0 as indicated by advpnc=1 in the logs
D is indeed the correct answer
we've been so used to tunnel names with NAME_NUMBER, thus the confusion that letter A is the correct one
but we need to remember that as long as advpnsc=1, that means that tunnel is a shortcut tunnel. for this example, the parent tunnel is likely named only T_MPLS (no number)
D is correct
When reviewing VPN log messages, the field advpnsc will help you identify the shortcut VPN tunnels.
FortiGate will set advpnsc value 1 for any log messages related to shortcut tunnels; for any other tunnel, the
advpnsc value is set to 0.
There is one shortcut built over T_MPLS_0 because second log has "advpnsc=1" and page 283 says "FortiGate will set advpnsc value 1 for any log messages related to shortcut tunnels; for any other tunnel, the advpnsc value is set to 0."
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
33f510d
1 week, 6 days agomader
1 month, 1 week agoSlikings
2 months agof002a32
2 months agoLothBrok007
1 month, 1 week agoFriedExams
2 months, 1 week agoccie8122
6 months agoshownoschmerz
8 months, 1 week agoluismanzanero
9 months, 1 week agosugar12
10 months, 4 weeks agorarasek3
11 months, 3 weeks agolucient
1 year agocannoe
2 months, 3 weeks agothepresidents83
6 months, 2 weeks agotruserud
1 year agoginmco
1 year ago