Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?
A . type must be set to static.
B . mode-cfg must be enabled.
C . exchange-interface-ip must be enabled.
D . add-route must be disabled.

Answer: D

Explanation:

for using "non ike" routes (for example BGP/static and so on) you must do disable the add-route that

inject automatically kernel route based on p2 selectors from the remote site from the SD-WAN_7.2_Study_Guide page 236

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments