NSE4 · Question #97
An administrator wants to create an IPsec VPN tunnel between two FortiGate devices. Which three configuration steps must be performed on both units to support this scenario? (Choose three.)
The correct answer is A. Create firewall policies to allow and control traffic between the source and destination IP D. Define the phase 2 parameters. E. Define the Phase 1 parameters. This question asks for three essential configuration steps required on both FortiGate devices to establish an IPsec VPN tunnel between them.
Question
An administrator wants to create an IPsec VPN tunnel between two FortiGate devices. Which three configuration steps must be performed on both units to support this scenario? (Choose three.)
Options
- ACreate firewall policies to allow and control traffic between the source and destination IP
- BConfigure the appropriate user groups to allow users access to the tunnel.
- CSet the operating mode to IPsec VPN mode.
- DDefine the phase 2 parameters.
- EDefine the Phase 1 parameters.
How the community answered
(18 responses)- A83% (15)
- B11% (2)
- C6% (1)
Why each option
This question asks for three essential configuration steps required on both FortiGate devices to establish an IPsec VPN tunnel between them.
Firewall policies are crucial for controlling which traffic is allowed to traverse the VPN tunnel once it is established, defining the source, destination, service, and action for traffic passing between the internal networks and the VPN interface.
Configuring user groups is relevant for client-to-site VPNs or user-based access control, but it's not a mandatory step for establishing a basic site-to-site IPsec tunnel between two FortiGate devices.
FortiGates operate in various modes, but there isn't a specific 'IPsec VPN mode' for the entire device; IPsec VPNs are a feature configured within the device's existing operating mode.
Phase 2 parameters define the security associations for the actual data tunnel, including encryption and authentication algorithms for data transfer, PFS settings, and key lifetimes, which must match on both VPN peers for the tunnel to establish.
Phase 1 parameters, or the Internet Key Exchange (IKE) phase, define how VPN peers authenticate and establish a secure channel for exchanging Phase 2 keys, and these settings must be identical on both FortiGates.
Concept tested: FortiGate site-to-site IPsec VPN basic configuration
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/52643/example-configuring-a-route-based-vpn
Topics
Community Discussion
No community discussion yet for this question.