NSE 8 – Network Security Expert — Question 1

There is an interface-mode IPsec tunnel configured between FortiGate1 and FortiGate2. You want to run OSPF over the IPsec tunnel. On both FortiGates. the
IPsec tunnel is based on physical interface port1. Port1 has the default MTU setting on both FortiGate units.
Which statement is true about this scenario?

Answer options

Correct answer: B

Explanation

The correct answer is B because OSPF requires the MTU to be set explicitly in its interface configuration to avoid issues with packet fragmentation. Options A and D are incorrect as they pertain to multicast policies and IP address assignments, which are not necessary for OSPF operation in this context. Option C is also incorrect because the MTU needs to be set in the OSPF settings, not the IPsec interface.