FCSS_SDW_AR-7.4 · Question #3
Refer to the exhibit. The administrator configured the IPsec tunnel VPN1 on a FortiGate device with the parameters shown in exhibit. Based on the configuration, which three conclusions can you draw…
The correct answer is C. The administrator must manually assign the tunnel interface IP address on the hub side D. The remote end must support IKEv2. E. This configuration allows user-defined overlay IP addresses. The administrator must manually assign the tunnel interface IP address on the hub side The setting "set exchange-interface-ip enable" means the tunnel interface IP address is exchanged, but the hub side IP must be set manually. The remote end must support IKEv2 The command "set…
Question
Refer to the exhibit. The administrator configured the IPsec tunnel VPN1 on a FortiGate device with the parameters shown in exhibit. Based on the configuration, which three conclusions can you draw about the characteristics and requirements of the VPN tunnel? (Choose three.)
Exhibit
Options
- AThe tunnel interface IP address on the spoke side is provided by the hub.
- BThe remote end can be a third-party IPsec device.
- CThe administrator must manually assign the tunnel interface IP address on the hub side
- DThe remote end must support IKEv2.
- EThis configuration allows user-defined overlay IP addresses.
How the community answered
(47 responses)- A17% (8)
- B9% (4)
- C74% (35)
Explanation
The administrator must manually assign the tunnel interface IP address on the hub side The setting "set exchange-interface-ip enable" means the tunnel interface IP address is exchanged, but the hub side IP must be set manually. The remote end must support IKEv2 The command "set ike-version 2" explicitly configures IKE version 2 for this tunnel, so the remote device must support IKEv2. This configuration allows user-defined overlay IP addresses The tunnel interface enables user control over IP addressing for the overlay network, allowing custom IP assignments.
Topics
Community Discussion
No community discussion yet for this question.
