FCP_FGT_AD-7.6 · Question #50
You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic. In which two ways can you effectively resolve the problem? (Choose two.)
The correct answer is A. You can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500 B. You can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP. The training is basically trying to point out the advantage of FortiGate's SSL VPN over IPSec VPN in situation where issues are caused by an intermediate device. IPsec uses ESP and UDP 500 and 4500, so where these are blocked, SSL VPN tunnel mode shines because it uses HTTPS…
Question
You are encountering connectivity problems caused by intermediate devices blocking IPsec traffic. In which two ways can you effectively resolve the problem? (Choose two.)
Options
- AYou can use SSL VPN tunnel mode to prevent problems with blocked ESP and UDP ports (500
- BYou can configure a hub-and-spoke topology with SSL VPN tunnels to bypass blocked UDP
- CYou can turn on fragmentation to fix large certificate negotiation problems.
- DYou should use the protocol IKEv2.
How the community answered
(18 responses)- A78% (14)
- C6% (1)
- D17% (3)
Explanation
The training is basically trying to point out the advantage of FortiGate's SSL VPN over IPSec VPN in situation where issues are caused by an intermediate device. IPsec uses ESP and UDP 500 and 4500, so where these are blocked, SSL VPN tunnel mode shines because it uses HTTPS (443) and TLS by default (both TCP). Again where UDP ports are blocked, SSL VPN shines (Tunnel mode Hub and Spoke) because it does not use UDP.
Topics
Community Discussion
No community discussion yet for this question.