NSE4 · Question #404
Which of the following statements are correct concerning the IPsec phase 1 and phase 2, shown in the exhibit? (choose two)
The correct answer is C. The FortiGate device will automatically add a static route to the source quick mode selector D. The configuration will work only to establish FortiClient-to-FortiGate tunnels. A FortiGate tunnel. Based on typical FortiGate IPsec configurations, the device can automatically add a static route for the VPN tunnel, and a specific setup might be intended solely for FortiClient-to-FortiGate connections.
Question
Which of the following statements are correct concerning the IPsec phase 1 and phase 2, shown in the exhibit? (choose two)
Exhibit
Options
- AThe quick mode selector in the remote site must also be 0.0.0.0/0 for the source and
- BOnly remote peers with the peer ID 'fortinet' will be able to establish a VPN.
- CThe FortiGate device will automatically add a static route to the source quick mode selector
- DThe configuration will work only to establish FortiClient-to-FortiGate tunnels. A FortiGate tunnel
How the community answered
(16 responses)- A19% (3)
- B6% (1)
- C75% (12)
Why each option
Based on typical FortiGate IPsec configurations, the device can automatically add a static route for the VPN tunnel, and a specific setup might be intended solely for FortiClient-to-FortiGate connections.
For a VPN to establish correctly, the remote site's *local* quick mode selector must match the local site's *remote* quick mode selector; they don't both universally have to be 0.0.0.0/0, especially in site-to-site scenarios.
While a specific peer ID limits which remote peers can establish *this specific tunnel*, it does not limit the establishment of *other* VPNs or imply that only FortiGate devices can connect, as other vendors could use the same ID.
When `set add-route enable` is configured in an IPsec phase 2, the FortiGate automatically adds a static route for the protected network (defined by the quick mode selector) pointing to the VPN tunnel interface.
A VPN configuration with broad phase 2 selectors (e.g., 0.0.0.0/0 for both source and destination) and potentially a specific peer ID often indicates a configuration designed for FortiClient dial-up VPNs, rather than site-to-site VPNs with another FortiGate.
Concept tested: FortiGate IPsec VPN configuration logic (client VPNs, route addition)
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/52678/ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.
