NSE4 · Question #64
Which statements are correct regarding an IPv6 over IPv4 IPsec configuration? (Choose two.)
The correct answer is B. The destination quick mode selector must be an IPv6 address. C. The Local Gateway IP must be an IPv4 address. This question addresses the specific addressing requirements for configuring an IPv6 over IPv4 IPsec tunnel.
Question
Which statements are correct regarding an IPv6 over IPv4 IPsec configuration? (Choose two.)
Options
- AThe source quick mode selector must be an IPv4 address.
- BThe destination quick mode selector must be an IPv6 address.
- CThe Local Gateway IP must be an IPv4 address.
- DThe remote gateway IP must be an IPv6 address.
How the community answered
(14 responses)- A14% (2)
- B79% (11)
- D7% (1)
Why each option
This question addresses the specific addressing requirements for configuring an IPv6 over IPv4 IPsec tunnel.
The source quick mode selector must be an IPv6 address, as it specifies the IPv6 traffic that the tunnel is encapsulating and protecting.
For an IPv6 over IPv4 IPsec tunnel, the quick mode selectors define the actual traffic being protected, which is IPv6, so the destination quick mode selector must be an IPv6 address.
The Local Gateway IP refers to the FortiGate's external interface IP address for the tunnel, which, in an IPv6 over IPv4 setup, must be an IPv4 address to establish the underlying tunnel.
The remote gateway IP is the IP address of the peer IPsec gateway on the underlying network, which for an IPv6 over IPv4 tunnel must be an IPv4 address.
Concept tested: IPv6 over IPv4 IPsec tunnel configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/523194/ipv6-over-ipv4-ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.