NSE4 · Question #382
Which of the following statements are correct concerning IPsec dialup VPN configurations for FortiGate devices? (Choose two)
The correct answer is C. Peer ID must be used when there is more than one aggressive-mode IPsec dialup VPN on the D. The FortiGate will automatically add a static route to the source quick mode selector address. When configuring multiple aggressive-mode IPsec dialup VPNs on a FortiGate, a unique Peer ID is required for each, and the FortiGate automatically adds a static route for the quick mode selector's destination.
Question
Which of the following statements are correct concerning IPsec dialup VPN configurations for FortiGate devices? (Choose two)
Options
- AMain mode mist be used when there is no more than one IPsec dialup VPN configured on the
- BA FortiGate device with an IPsec VPN configured as dialup can initiate the tunnel connection to
- CPeer ID must be used when there is more than one aggressive-mode IPsec dialup VPN on the
- DThe FortiGate will automatically add a static route to the source quick mode selector address
How the community answered
(56 responses)- A7% (4)
- B13% (7)
- C80% (45)
Why each option
When configuring multiple aggressive-mode IPsec dialup VPNs on a FortiGate, a unique Peer ID is required for each, and the FortiGate automatically adds a static route for the quick mode selector's destination.
While main mode offers enhanced security and is often preferred for site-to-site VPNs, aggressive mode is commonly used for dial-up VPNs regardless of the number of tunnels due to its faster negotiation, and its use is not strictly limited by the count of VPNs.
A FortiGate device configured as an IPsec dialup VPN server acts as a listener and waits for remote clients to initiate the tunnel connection; it cannot initiate a dialup connection itself.
When configuring multiple aggressive-mode IPsec dialup VPNs on a FortiGate, a unique Peer ID is essential for the FortiGate to correctly distinguish and apply the appropriate tunnel configuration for each connecting client.
Upon successful establishment of an IPsec dialup VPN tunnel, the FortiGate automatically adds a static route for the remote client's network (defined by the quick mode selector's destination address) through the VPN interface, simplifying routing management.
Concept tested: FortiGate IPsec dialup VPN configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/119934/ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.