Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE7_EFW-7.2 Topic 5 Question 24 Discussion

Actual exam question for Fortinet's NSE7_EFW-7.2 exam
Question #: 24
Topic #: 5
[All NSE7_EFW-7.2 Questions]

You want to improve reliability over a lossy IPSec tunnel.

Which combination of IPSec phase 1 parameters should you configure?

Show Suggested Answer Hide Answer
Suggested Answer: C

For improving reliability over a lossy IPSec tunnel, the fragmentation and fragmentation-mtu parameters should be configured. In scenarios where there might be issues with packet size or an unreliable network, setting the IPsec phase 1 to allow for fragmentation will enable large packets to be broken down, preventing them from being dropped due to size or poor network quality. The fragmentation-mtu specifies the size of the fragments. This is aligned with Fortinet's recommendations for handling IPsec VPN over networks with potential packet loss or size limitations.


Contribute your Thoughts:

Loreen
2 days ago
D) keepalive and keylive? Really? Sounds like someone's been watching too many spy movies. Let's keep it technical, folks!
upvoted 0 times
...
Melissa
10 days ago
I'm not sure, but I think C) fragmentation and fragmentation-mtu could also be a good option.
upvoted 0 times
...
Slyvia
13 days ago
Wait, 'keylive'? Is that like a new dance move or something? I'm pretty sure that's not an actual IPSec parameter.
upvoted 0 times
Tina
3 days ago
A) fec-ingress and fec-egress
upvoted 0 times
...
...
Tamar
17 days ago
I agree with Matthew, because keepalive and keylive can help improve reliability.
upvoted 0 times
...
Matthew
21 days ago
I think the answer is D) keepalive and keylive.
upvoted 0 times
...
Jenelle
24 days ago
I think C) fragmentation and fragmentation-mtu is the way to go. Improving reliability over a lossy IPSec tunnel requires handling fragmentation, right?
upvoted 0 times
Dominque
2 days ago
A) fec-ingress and fec-egress are also important for improving reliability.
upvoted 0 times
...
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77