NSE4 · Question #359
Which statements about an IPv6-over-IPv4 IPsec configuration are correct? (Choose two.)
The correct answer is C. The local gateway IP must an IPv4 address. D. The destination quick mode selector must be an IPv6 address. In an IPv6-over-IPv4 IPsec configuration, the local and remote gateways use IPv4 addresses to establish the tunnel, while the traffic being secured and tunneled (quick mode selectors) is IPv6.
Question
Which statements about an IPv6-over-IPv4 IPsec configuration are correct? (Choose two.)
Options
- AThe remote gateway IP must be an IPv6 address.
- BThe source quick mode selector must be an IPv4 address.
- CThe local gateway IP must an IPv4 address.
- DThe destination quick mode selector must be an IPv6 address.
How the community answered
(24 responses)- A8% (2)
- B17% (4)
- C75% (18)
Why each option
In an IPv6-over-IPv4 IPsec configuration, the local and remote gateways use IPv4 addresses to establish the tunnel, while the traffic being secured and tunneled (quick mode selectors) is IPv6.
The remote gateway IP must be an IPv4 address because the tunnel is built over an IPv4 network, carrying IPv6 traffic.
The source quick mode selector defines the source of the traffic being encapsulated, which in an IPv6-over-IPv4 tunnel is IPv6 traffic.
Since the tunnel is 'IPv6-over-IPv4', the underlying IPsec tunnel endpoints (gateways) are established using IPv4 addresses. Thus, the local gateway IP must be an IPv4 address.
The purpose of an IPv6-over-IPv4 IPsec tunnel is to securely transport IPv6 traffic. Therefore, the destination quick mode selector, which defines the encapsulated traffic, must be an IPv6 address.
Concept tested: IPv6-over-IPv4 IPsec tunnel configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/25390/ipv6-ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.