nerdexam
Fortinet

FCSS_EFW_AD-7.6 · Question #3

The IT department discovered during the last network migration that all zero phase selectors in phase 2 IPsec configurations impacted network operations. What are two valid approaches to prevent…

The correct answer is A. Use routing protocols to specify allowed subnets over the tunnel. C. Clearly indicate to the VPN which segments will be encrypted in the phase two selectors. Zero phase selectors in IPsec Phase 2 mean that no specific traffic selectors (subnets) are defined, allowing any traffic to be encrypted through the VPN tunnel. This can cause unintended traffic forwarding issues and disrupt network operations. To prevent this from happening…

VPN

Question

The IT department discovered during the last network migration that all zero phase selectors in phase 2 IPsec configurations impacted network operations. What are two valid approaches to prevent this during future migrations? (Choose two.)

Options

  • AUse routing protocols to specify allowed subnets over the tunnel.
  • BConfigure an IPsec-aggregate to create redundancy between each firewall peer.
  • CClearly indicate to the VPN which segments will be encrypted in the phase two selectors.
  • DConfigure an IP address on the IPsec interface of each firewall to establish unique peer

How the community answered

(46 responses)
  • A
    80% (37)
  • B
    13% (6)
  • D
    7% (3)

Explanation

Zero phase selectors in IPsec Phase 2 mean that no specific traffic selectors (subnets) are defined, allowing any traffic to be encrypted through the VPN tunnel. This can cause unintended traffic forwarding issues and disrupt network operations. To prevent this from happening during future migrations: Using routing protocols ensures that only specific subnets are advertised over the tunnel. Dynamic routing (such as OSPF or BGP) helps define which networks should use the tunnel, preventing unintended traffic from being encrypted. Clearly defining phase 2 selectors avoids the problem of encrypting all traffic by explicitly stating the allowed source and destination subnets. This prevents the tunnel from affecting unrelated network traffic.

Topics

#IPsec#phase 2 selectors#VPN migration#routing over tunnel

Community Discussion

No community discussion yet for this question.

Full FCSS_EFW_AD-7.6 Practice