Question 1

Refer to the exhibit, which shows a network diagram showing the addition of site 2 with an overlapping network segment to the existing VPN IPsec connection between the hub and site 1.

Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?
  • Question 2

    Refer to the exhibit. A pre-run CLI template that is used in zero-touch provisioning (ZTP) and low- touch provisioning (LTP) with FortiManager is shown.

    The template is not assigned even though the configuration has already been installed on FortiGate.
    What is true about this scenario?
  • Question 3

    Refer to the exhibits.



    The routing tables of FortiGate_A and FortiGate_B, and a network topology are shown.
    Why does FortiGate_B have only one external route available to 100.75.5.1/32?
  • Question 4

    Refer to the exhibit, which shows the HA status of an active-passive cluster.
    An administrator wants FortiGate_B to handle the Core2 VDOM traffic.
    Which modification must the administrator apply to achieve this?
  • Question 5

    During the maintenance window, an administrator must sniff all the traffic going through a specific firewall policy, which is handled by NP6 interfaces. The output of the sniffer trace provides just a few packets.
    Why is the output of sniffer trace limited?