The SD-WAN 7.6 Enterprise Administrator Study Guide identifies the recommended BGP-on-loopback IPsec settings. For branches, it specifies:
“Static tunnel type (remote end IP address is known).”
“net-device enable.”
Enabling net-device on the spoke creates a kernel interface for the tunnel. This assists with tunnel monitoring and management and is required to support ADVPN shortcut tunnels. Dynamic BGP establishes on-demand BGP peerings between spokes after an ADVPN shortcut is created; therefore, the spoke must support those dynamic shortcut interfaces. This makes option C correct.
The spoke should also configure localid. The FortiOS 7.6 Administrator Study Guide explains: “Local ID: if the peer accepts a specific peer ID, type that same peer ID in this field.” The local ID supplies the spoke’s IKE identity to the dial-up hub, allowing the hub to identify and authenticate the connecting spoke correctly. Therefore, option D is correct.
Option A reverses the recommended roles. The hub must use a dynamic tunnel type because it operates as the dial-up server and does not require every spoke’s changing public gateway address in advance.
Option B is also incorrect. The guide states: “There is no need to configure any tunnel IP address, so the IKE Mode Config is not used.” BGP on loopback uses the loopback address and exchange-interface-ip instead of IKE mode configuration.
[References: SD-WAN 7.6 Enterprise Administrator Study Guide, SD-WAN Overlay Design and Best Practices, pages 118–119 and 122; FortiOS 7.6 Administrator Study Guide, IPsec VPN – Phase 1 Network Settings, page 375; FortiOS 7.6 – BGP on loopback., , , ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit