NSE4 · Question #413
What is required in a FortiGate configuration to have more than one dialup IPsec VPN using aggressive mode?
The correct answer is C. Each aggressive mode dialup MUST accept connections from different peer ID. To configure multiple aggressive mode dialup IPsec VPNs on a FortiGate, each VPN must be configured to accept connections from a unique peer ID.
Question
What is required in a FortiGate configuration to have more than one dialup IPsec VPN using aggressive mode?
Options
- AAll the aggressive mode dialup VPNs MUST accept connections from the same peer ID.
- BEach peer ID MUST match the FQDN of each remote peer.
- CEach aggressive mode dialup MUST accept connections from different peer ID.
- DThe peer ID setting must NOT be used.
How the community answered
(53 responses)- A2% (1)
- B2% (1)
- C92% (49)
- D4% (2)
Why each option
To configure multiple aggressive mode dialup IPsec VPNs on a FortiGate, each VPN must be configured to accept connections from a unique peer ID.
Using the same peer ID for multiple aggressive mode dialup VPNs would prevent the FortiGate from correctly identifying and authenticating different remote clients, leading to connection failures.
While an FQDN can be used as a peer ID, it is not a mandatory requirement for every remote peer; other forms of identification, like an IP address or user FQDN, are also valid.
In aggressive mode, the FortiGate relies on the Peer ID to uniquely identify and authenticate each remote dialup client during Phase 1 negotiation, therefore requiring different peer IDs for each distinct VPN tunnel.
The peer ID setting is essential for identifying and authenticating aggressive mode dialup clients; not using it would prevent the establishment of the VPN.
Concept tested: Aggressive mode IPsec dialup peer ID
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/708579/configuring-ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.