nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #41

Refer to the exhibit, which contains partial output from an IKE real-time debug. The administrator does not have access to the remote gateway. Based on the debug output, which configuration change…

The correct answer is A. In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms. Add an AES256‑SHA256 proposal to your local Phase 1 settings so that the FortiGate can match the peer's AES‑CBC/256 with SHA‑256 proposal.

VPN Troubleshooting

Question

Refer to the exhibit, which contains partial output from an IKE real-time debug. The administrator does not have access to the remote gateway. Based on the debug output, which configuration change the administrator make to the local gateway to resolve the phase 1 negotiation error?

Exhibit

FCSS_NST_SE-7.4 question #41 exhibit

Options

  • AIn the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
  • BIn the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
  • CIn the phase 1 network configuration, set the IKE version to 2.
  • DIn the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.

How the community answered

(29 responses)
  • A
    76% (22)
  • B
    7% (2)
  • C
    14% (4)
  • D
    3% (1)

Explanation

Add an AES256‑SHA256 proposal to your local Phase 1 settings so that the FortiGate can match the peer's AES‑CBC/256 with SHA‑256 proposal.

Topics

#IKE debug#phase 1 proposal#encryption algorithm#VPN negotiation

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice