NSE4 · Question #438
Which portion of the configuration does an administrator specify the type of IPsec configuration (either policy-based or route-based)?
The correct answer is D. Under the firewall policy settings.. The type of IPsec configuration (policy-based or route-based) is determined by how the VPN is integrated into the firewall policy, which directs traffic to the VPN tunnel.
Question
Which portion of the configuration does an administrator specify the type of IPsec configuration (either policy-based or route-based)?
Options
- AUnder the IPsec VPN global settings.
- BUnder the phase 2 settings.
- CUnder the phase 1 settings.
- DUnder the firewall policy settings.
How the community answered
(49 responses)- A2% (1)
- B2% (1)
- C8% (4)
- D88% (43)
Why each option
The type of IPsec configuration (policy-based or route-based) is determined by how the VPN is integrated into the firewall policy, which directs traffic to the VPN tunnel.
Global settings typically apply to general VPN parameters or common settings, not the fundamental type of traffic routing for a specific VPN.
Phase 2 settings define the IPsec Security Association (SA) parameters, such as encryption and authentication algorithms, but do not determine the VPN type.
Phase 1 settings establish the IKE Security Association (SA) for secure key exchange parameters like encryption, authentication, and lifetime, which is independent of the VPN type.
On devices like FortiGate, the choice between policy-based and route-based IPsec is implicitly made when configuring the firewall policy that utilizes the VPN, either by specifying traffic selectors (policy-based) or by selecting an IPsec tunnel interface (route-based).
Concept tested: IPsec VPN policy type configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/867295/policy-based-vs-route-based-ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.