nerdexam
Fortinet

FCP_FGT_AD-7.4 · Question #13

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has…

The correct answer is B. On Remote-FortiGate, set port2 as Interface. D. On HQ-FortiGate, set IKE mode to Main (ID protection). In IKEv1, there are two possible modes in which the IKE SA negotiation can take place: mail and aggressive mode. The settings on both ends must agree; otherwise, phase 1 negotiation fails and both IPsec peers are not able to establish a secure channel.

VPN

Question

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match. Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)

Exhibit

FCP_FGT_AD-7.4 question #13 exhibit

Options

  • AOn HQ-FortiGate, disable Diffie-Helman group 2.
  • BOn Remote-FortiGate, set port2 as Interface.
  • COn both FortiGate devices, set Dead Peer Detection to On Demand.
  • DOn HQ-FortiGate, set IKE mode to Main (ID protection).

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    83% (25)
  • C
    10% (3)

Explanation

In IKEv1, there are two possible modes in which the IKE SA negotiation can take place: mail and aggressive mode. The settings on both ends must agree; otherwise, phase 1 negotiation fails and both IPsec peers are not able to establish a secure channel.

Topics

#IPsec#phase 1#IKE mode#interface configuration

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.4 Practice