NSE4 · Question #372
Which of the following IPsec configuration modes can be used for implementing L2TP- over- IPSec VPNs?
The correct answer is A. Policy-based IPsec only. L2TP-over-IPSec VPNs can only be implemented using policy-based IPsec configurations, as route-based IPsec is not designed for tunnel mode with L2TP.
Question
Which of the following IPsec configuration modes can be used for implementing L2TP- over- IPSec VPNs?
Options
- APolicy-based IPsec only.
- BRoute-based IPsec only.
- CBoth policy-based and route-based VPN.
- DL2TP-over-IPSec is not supported by FortiGate devices.
How the community answered
(22 responses)- A91% (20)
- B5% (1)
- D5% (1)
Why each option
L2TP-over-IPSec VPNs can only be implemented using policy-based IPsec configurations, as route-based IPsec is not designed for tunnel mode with L2TP.
L2TP-over-IPSec VPNs are implemented using policy-based IPsec, where the FortiGate applies policies to specific traffic based on source, destination, and service, rather than routing traffic through a dedicated tunnel interface.
Route-based IPsec creates a virtual tunnel interface and routes traffic through it, which is not the mechanism used for L2TP-over-IPSec VPNs.
L2TP-over-IPSec VPNs specifically utilize policy-based IPsec and cannot be implemented with route-based IPsec.
L2TP-over-IPSec is fully supported by FortiGate devices, using policy-based IPsec.
Concept tested: IPsec modes for L2TP-over-IPSec
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/500078/vpn-settings
Topics
Community Discussion
No community discussion yet for this question.