NSE4 · Question #350
An administrator has configured a route-based IPsec VPN between two FortiGates. Which statement about this IPsec VPN configuration is true?
The correct answer is D. A virtual IPsec interface is automatically created after the phase 1 configuration is completed.. When configuring a route-based IPsec VPN on FortiGate, a virtual IPsec interface is automatically generated upon completion of the phase 1 configuration.
Question
An administrator has configured a route-based IPsec VPN between two FortiGates. Which statement about this IPsec VPN configuration is true?
Options
- AA phase 2 configuration is not required.
- BThis VPN cannot be used as part of a hub and spoke topology.
- CThe IPsec firewall policies must be placed at the top of the list.
- DA virtual IPsec interface is automatically created after the phase 1 configuration is completed.
How the community answered
(26 responses)- A4% (1)
- C4% (1)
- D92% (24)
Why each option
When configuring a route-based IPsec VPN on FortiGate, a virtual IPsec interface is automatically generated upon completion of the phase 1 configuration.
Both Phase 1 (IKE Security Association) and Phase 2 (IPsec Security Association) configurations are essential and required components for establishing and maintaining any IPsec VPN tunnel.
Route-based IPsec VPNs are highly suitable and frequently used for hub-and-spoke topologies, as they allow for flexible routing and dynamic tunnel management.
The placement of IPsec firewall policies in the policy list follows the standard FortiGate policy evaluation order, based on matching criteria, and they do not inherently need to be at the top.
For route-based IPsec VPNs, completing the Phase 1 configuration automatically creates a virtual IPsec interface, which acts as a logical network interface that can be used in routing tables and firewall policies.
Concept tested: FortiGate route-based IPsec VPN
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/920038/route-based-ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.