New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Newly Released Fortinet NSE8_811 Exam PDF

Page: 2 / 2
Total 65 questions

Fortinet NSE 8 Written Exam (NSE8_811) Questions and Answers

Question 5

You are building a FortiGala cluster which is stretched over two locations. The HA connections for the cluster are terminated on the data centers. Once the FortiGates have booted, they do form a cluster. The network operators inform you that CRC eoors are present on the switches where the FortiGAtes are connected.

What would you do to solve this problem?

Options:

A.

Replace the caables where the CRC errors occur.

B.

Change the ethertype for the HA packets.

C.

Set the speedduplex setting to 1 Gbps /Full Duplex.

D.

Place the HA interfaces in dedicated VLANs.

Question 6

You want to manage a FortiCloud service. The FortiGate shows up in your list devices on the FortiCloud Web site, but all management functions are either missing or grayed out.

Which statement a correct in this scenario?

Options:

A.

The managed FcrtGate a running a version of ForflOS that is either too new or too for FortCloud.

B.

The managed FortiGate requires that a FortiCloud management license be purchased and applied.

C.

You must manually configure system control-management on the FortiGate CLI and set the management type to fortiguard.

D.

The management tunnel mode on the managed FortiGate must be changed to normal.

Question 7

Exhibit

Click the Exhibit button.

A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it.

However, FortiGates A and B have problems connecting to the VPN. Only one of them can be connected at a time. If site B tries to connect white site A is connected, site A is disconnected. The IKE real time debug shows the output in the exhibit when site A is disconnected.

Which configuration setting should be executed in the dial-up configuration to allow both VPNs to be connected at the same time?

Options:

A.

set enforce-unique-id disable

B.

set add-router enable

C.

set single-source disable

D.

set router-overlap allow

Question 8

Click the Exhibit button.

A FortiGate with the default configuration is deployed between two IP phones. FortiGate receives the INVITE request shown in the exhibit form Phone A (internal)to Phone B (external). Which two actions are taken by the FortiGate after the packet is received? (Choose two.)

Options:

A.

A pinhole will be opened to accept traffic sent to FortiGate's WAN IP address and ports 49169 and 49170.

B.

a pinhole will be opened to accept traffic sent to FortiGate's WAN IP address and ports 49l70 and 49171.

C.

The phone A IP address will be translated lo the WAN IP address in all INVITE header fields and the m: field of the SDP statement.

D.

The phone A IP address will be translated for the WAN IP address in all INVITE header fields and the SDP statement remains intact.

Page: 2 / 2
Total 65 questions