NSE4 · Question #494
Review the IPsec phase 1 configuration in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)
The correct answer is A. The remote gateway address is 10.200.3.1 C. The local gateway IP is the address assigned to port1. In an IPsec Phase 1 configuration, the remote gateway specifies the peer's public IP address, and the local gateway is determined by the IP address of the FortiGate's designated local interface.
Question
Review the IPsec phase 1 configuration in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)
Exhibit
Options
- AThe remote gateway address is 10.200.3.1
- BThe local IPsec interface address is 10.200.3.1
- CThe local gateway IP is the address assigned to port1
- DThe local gateway IP is 10.200.3.1
How the community answered
(33 responses)- A76% (25)
- B18% (6)
- D6% (2)
Why each option
In an IPsec Phase 1 configuration, the remote gateway specifies the peer's public IP address, and the local gateway is determined by the IP address of the FortiGate's designated local interface.
In the IPsec Phase 1 configuration, the `Remote Gateway` field is used to specify the public IP address of the peer device with which the FortiGate will establish the VPN tunnel, indicating that 10.200.3.1 is the remote endpoint.
If 10.200.3.1 is specified as the remote gateway, it cannot simultaneously be the local IPsec interface address.
The `Local Interface` selected in the Phase 1 configuration dictates which FortiGate interface will handle the VPN connection, and its assigned IP address will serve as the local gateway IP for the IPsec tunnel.
This statement contradicts choice A and implies 10.200.3.1 is the FortiGate's local VPN endpoint, which is incorrect if it's configured as the remote gateway.
Concept tested: FortiGate IPsec Phase 1 configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/142994/phase-1-settings
Topics
Community Discussion
No community discussion yet for this question.
