nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #107

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has…

The correct answer is A. On HQ-FortiGate, set IKE mode to Main (ID protection). B. On Remote-FortiGate, set port2 as Interface. On the HQ-FortiGate the IKE phase 1 mode is set to Aggressive, while on the Remote-FortiGate it is set to Main (ID protection). Both sides must use the same IKE mode for phase 1 to come up, so changing HQ-FortiGate to Main mode resolves this mismatch. On the Remote-FortiGate…

Submitted by priya_blr· Apr 18, 2026VPN

Question

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re- entered the pre-shared key on both FortiGate devices to make sure they match. Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)

Exhibit

FCP_FGT_AD-7.6 question #107 exhibit

Options

  • AOn HQ-FortiGate, set IKE mode to Main (ID protection).
  • BOn Remote-FortiGate, set port2 as Interface.
  • COn HQ-FortiGate, disable Diffie-Helman group 2.
  • DOn both FortiGate devices, set Dead Peer Detection to On Demand.

How the community answered

(64 responses)
  • A
    75% (48)
  • C
    17% (11)
  • D
    8% (5)

Explanation

On the HQ-FortiGate the IKE phase 1 mode is set to Aggressive, while on the Remote-FortiGate it is set to Main (ID protection). Both sides must use the same IKE mode for phase 1 to come up, so changing HQ-FortiGate to Main mode resolves this mismatch. On the Remote-FortiGate, the phase 1 Interface is configured as port1, but according to the diagram the WAN-facing interface with IP 10.10.200.10 is port2. The local interface in the IPsec configuration must match the physical WAN interface, so changing it to port2 is required for the tunnel to establish.

Topics

#IPsec VPN#Phase 1 troubleshooting#IKE mode#Interface configuration

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice