NSE4 · Question #546
Which of the following statements about policy-based IPsec tunnels are true? (Choose two.)
The correct answer is B. They can be configured in both NAT/Route and transparent operation modes. C. They require two firewall policies: one for each direction of traffic flow. Policy-based IPsec VPN tunnels can be deployed in both NAT/Route and transparent modes, and they fundamentally require two firewall policies for managing bidirectional traffic flow.
Question
Which of the following statements about policy-based IPsec tunnels are true? (Choose two.)
Options
- AThey support GRE-over-IPsec.
- BThey can be configured in both NAT/Route and transparent operation modes.
- CThey require two firewall policies: one for each direction of traffic flow.
- DThey support L2TP-over-IPsec.
How the community answered
(51 responses)- A4% (2)
- B94% (48)
- D2% (1)
Why each option
Policy-based IPsec VPN tunnels can be deployed in both NAT/Route and transparent modes, and they fundamentally require two firewall policies for managing bidirectional traffic flow.
GRE-over-IPsec is generally implemented with route-based IPsec VPNs, where GRE tunnels are built over the virtual IPsec interface, not typically with policy-based IPsec which uses traffic selectors.
Policy-based IPsec tunnels can be configured in both NAT/Route (gateway) mode and transparent (bridge) mode on a FortiGate, providing flexibility for different network architectures.
For policy-based IPsec VPNs, two firewall policies are essential: one policy to permit outbound traffic from the local network into the tunnel, and another policy to permit inbound return traffic from the tunnel to the local network.
L2TP-over-IPsec is a distinct VPN technology often used for remote access and is not a direct characteristic or general capability of policy-based IPsec tunnels for site-to-site connectivity.
Concept tested: FortiGate policy-based IPsec VPN characteristics
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/463691/policy-based-ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.