NSE4 · Question #422
Which of the following IPsec configuration modes can be used when the FortiGate is running in NAT mode?
The correct answer is B. Both policy-based and route-based VPN. FortiGate appliances operating in NAT mode are fully capable of supporting both policy-based and route-based IPSec VPN configurations.
Question
Which of the following IPsec configuration modes can be used when the FortiGate is running in NAT mode?
Options
- APolicy-based VPN only
- BBoth policy-based and route-based VPN.
- CRoute-based VPN only.
- DIPSec VPNs are not supported when the FortiGate is running in NAT mode.
How the community answered
(31 responses)- A3% (1)
- B87% (27)
- C6% (2)
- D3% (1)
Why each option
FortiGate appliances operating in NAT mode are fully capable of supporting both policy-based and route-based IPSec VPN configurations.
While policy-based VPNs are supported in NAT mode, they are not the only type; route-based VPNs are also fully supported.
In NAT/Route mode, a FortiGate functions as a Layer 3 device, enabling it to establish both policy-based VPNs (controlled by firewall policies) and route-based VPNs (which use virtual tunnel interfaces and routing tables).
While route-based VPNs are supported in NAT mode, they are not the only type; policy-based VPNs are also fully supported.
IPSec VPNs are a core security feature and are widely supported and commonly deployed when a FortiGate is operating in its default NAT mode.
Concept tested: FortiGate IPSec VPN modes in NAT mode
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/603403/vpn-configuration
Topics
Community Discussion
No community discussion yet for this question.