NSE4 · Question #44
Review the IPsec phase 1 configuration in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)
The correct answer is A. The remote gateway address on 10.200.3.1. C. The local gateway IP is the address assigned to port1. The IPsec phase 1 configuration specifies the remote peer's public IP address as 10.200.3.1 and defines the local gateway IP as the address assigned to the FortiGate's port1 interface.
Question
Review the IPsec phase 1 configuration in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)
Exhibit
Options
- AThe remote gateway address on 10.200.3.1.
- BThe local IPsec interface address is 10.200.3.1.
- CThe local gateway IP is the address assigned to port1.
- DThe local gateway IP address is 10.200.3.1.
How the community answered
(35 responses)- A94% (33)
- B3% (1)
- D3% (1)
Why each option
The IPsec phase 1 configuration specifies the remote peer's public IP address as 10.200.3.1 and defines the local gateway IP as the address assigned to the FortiGate's port1 interface.
The remote gateway address explicitly defines the public IP address of the peer VPN device (e.g., another FortiGate) to which the IPsec tunnel will establish its Phase 1 connection, in this case, 10.200.3.1.
The 'local IPsec interface address' refers to the IP on the FortiGate's interface used for the tunnel, but assuming 10.200.3.1 is the remote gateway (A is correct), it cannot simultaneously be the local interface address in a standard setup.
The local gateway IP is the source IP address that the FortiGate uses for IKE negotiations and for establishing the VPN tunnel, which is typically the IP address assigned to the specified outbound network interface (e.g., port1).
If the remote gateway IP address is 10.200.3.1 (as per choice A), then the local gateway IP address cannot also be 10.200.3.1 in a typical site-to-site IPsec VPN configuration without complex and unusual NAT scenarios.
Concept tested: IPsec Phase 1 gateway identification
Source: https://docs.fortinet.com/document/fortigate/7.4.0/cli-reference/169096/config-vpn-ipsec-phase1-interface
Topics
Community Discussion
No community discussion yet for this question.
