FCSS_NST_SE-7.4 · Question #41
Refer to the exhibit, which contains partial output from an IKE real-time debug. The administrator does not have access to the remote gateway. Based on the debug output, which configuration change…
The correct answer is A. In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms. Add an AES256‑SHA256 proposal to your local Phase 1 settings so that the FortiGate can match the peer's AES‑CBC/256 with SHA‑256 proposal.
Question
Refer to the exhibit, which contains partial output from an IKE real-time debug. The administrator does not have access to the remote gateway. Based on the debug output, which configuration change the administrator make to the local gateway to resolve the phase 1 negotiation error?
Exhibit
Options
- AIn the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
- BIn the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
- CIn the phase 1 network configuration, set the IKE version to 2.
- DIn the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.
How the community answered
(29 responses)- A76% (22)
- B7% (2)
- C14% (4)
- D3% (1)
Explanation
Add an AES256‑SHA256 proposal to your local Phase 1 settings so that the FortiGate can match the peer's AES‑CBC/256 with SHA‑256 proposal.
Topics
Community Discussion
No community discussion yet for this question.
