NSE4 · Question #549
Why must you use aggressive mode when a local FortiGate IPsec gateway hosts multiple dialup tunnels?
The correct answer is B. FortiClient supports aggressive mode. Aggressive mode is often required for a FortiGate hosting multiple IPsec dialup tunnels because FortiClient, a common remote peer, supports aggressive mode.
Question
Why must you use aggressive mode when a local FortiGate IPsec gateway hosts multiple dialup tunnels?
Options
- AThe FortiGate is able to handle NATed connections only with aggressive mode.
- BFortiClient supports aggressive mode.
- CThe remote peers are able to provide their peer IDs in the first message with aggressive mode.
- DMain mode does not support XAuth for user authentication.
How the community answered
(43 responses)- A5% (2)
- B91% (39)
- C2% (1)
- D2% (1)
Why each option
Aggressive mode is often required for a FortiGate hosting multiple IPsec dialup tunnels because FortiClient, a common remote peer, supports aggressive mode.
FortiGate can handle NATed connections in both main mode and aggressive mode with appropriate NAT traversal (NAT-T) settings.
FortiClient, a common VPN client used for dial-up IPsec VPNs, primarily supports IKEv1 aggressive mode for establishing connections. If the FortiGate gateway needs to support FortiClient connections from multiple remote users, configuring aggressive mode is necessary for compatibility.
While aggressive mode allows the peer ID to be sent in the first message, the primary reason for mandating aggressive mode in this scenario for a FortiGate gateway supporting multiple dialup tunnels is FortiClient compatibility, not solely the ID exchange mechanism.
Main mode can support XAuth for user authentication, especially when combined with Extended Authentication (XAuth) in Phase 1 negotiations.
Concept tested: IPsec Aggressive Mode for FortiGate Dial-up VPNs
Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-cookbook/249118/aggressive-mode-with-pre-shared-key-pki-and-xauth
Topics
Community Discussion
No community discussion yet for this question.