nerdexam
Fortinet

FCNSP · Question #118

A FortiClient fails to establish a VPN tunnel with a FortiGate unit. The following information is displayed in the FortiGate unit logs: msg="Initiator: sent 192.168.11.101 main mode message #1 (OK)"…

The correct answer is A. An IPSec DHCP server is not enabled on the external interface of the FortiGate unit. See the full explanation below for the reasoning.

Question

A FortiClient fails to establish a VPN tunnel with a FortiGate unit. The following information is displayed in the FortiGate unit logs:

msg="Initiator: sent 192.168.11.101 main mode message #1 (OK)" msg="Initiator: sent 192.168.11.101 main mode message #2 (OK)" msg="Initiator: sent 192.168.11.101 main mode message #3 (OK)" msg="Initiator: parsed 192.168.11.101 main mode message #3 (DONE)" msg="Initiator: sent 192.168.11.101 quick mode message #1 (OK)" msg="Initiator: tunnel 192.168.1.1/192.168.11.101 install ipsec sa" msg="Initiator: sent 192.168.11.101 quick mode message #2 (DONE)" msg="Initiator: tunnel 192.168.11.101, transform=ESP_3DES, HMAC_MD5" msg="Failed to acquire an IP address Which of the following statements is a possible cause for the failure to establish the VPN tunnel?

Options

  • AAn IPSec DHCP server is not enabled on the external interface of the FortiGate unit.
  • BThere is no IPSec firewall policy configured for the policy-based VPN.
  • CThere is a mismatch between the FortiGate unit and the FortiClient IP addresses in the phase 2 settings.
  • DThe phase 1 configuration on the FortiGate unit uses Aggressive mode while FortiClient uses Main mode.

How the community answered

(39 responses)
  • A
    82% (32)
  • B
    3% (1)
  • C
    5% (2)
  • D
    10% (4)

Community Discussion

No community discussion yet for this question.

Full FCNSP Practice