NSE4 · Question #115
In an IPSec gateway-to-gateway configuration, two FortiGate units create a VPN tunnel between two separate private networks. Which of the following configuration steps must be performed on both…
The correct answer is A. Create firewall policies to control traffic between the IP source and destination address. D. Define the Phase 2 parameters that the FortiGate unit needs to create a VPN tunnel with the E. Define the Phase 1 parameters that the FortiGate unit needs to authenticate the remote peers. IPSec gateway-to-gateway VPNs require defining Phase 1 and Phase 2 parameters on both FortiGates for tunnel establishment and creating firewall policies for traffic flow.
Question
In an IPSec gateway-to-gateway configuration, two FortiGate units create a VPN tunnel between two separate private networks. Which of the following configuration steps must be performed on both FortiGate units to support this configuration? (Select all that apply.)
Options
- ACreate firewall policies to control traffic between the IP source and destination address.
- BConfigure the appropriate user groups on the FortiGate units to allow users access to the IPSec
- CSet the operating mode of the FortiGate unit to IPSec VPN mode.
- DDefine the Phase 2 parameters that the FortiGate unit needs to create a VPN tunnel with the
- EDefine the Phase 1 parameters that the FortiGate unit needs to authenticate the remote peers.
How the community answered
(55 responses)- A78% (43)
- B7% (4)
- C15% (8)
Why each option
IPSec gateway-to-gateway VPNs require defining Phase 1 and Phase 2 parameters on both FortiGates for tunnel establishment and creating firewall policies for traffic flow.
Firewall policies must be created on both FortiGate units to explicitly permit traffic to flow between the protected private networks through the IPSec VPN tunnel.
User groups are relevant for client-to-site VPNs (e.g., remote access) where individual users authenticate, not typically for gateway-to-gateway IPSec VPNs which connect networks.
FortiGate units operate in modes like NAT/Route or Transparent, and IPSec VPN is a feature configured within these modes, not a separate operating mode itself.
Phase 2 parameters, which define the security associations for the actual data transfer (encryption and integrity algorithms, key lifetimes), must be configured on both peers.
Phase 1 parameters, which define how the peers authenticate each other and establish a secure channel for exchanging Phase 2 keys, must be configured identically on both peers.
Concept tested: IPSec gateway-to-gateway configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/867946/ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.