NSE4 · Question #99
An administrator has configured a route-based site-to-site IPsec VPN. Which statement is correct regarding this IPsec VPN configuration?
The correct answer is D. A virtual IPsec interface is automatically created after the Phase 1 configuration is completed. The question asks for a correct statement about a route-based site-to-site IPsec VPN configuration.
Question
An administrator has configured a route-based site-to-site IPsec VPN. Which statement is correct regarding this IPsec VPN configuration?
Options
- AThe IPsec firewall policies must be placed at the top of the list.
- BThis VPN cannot be used as part of a hub and spoke topology.
- CRoutes are automatically created based on the quick mode selectors.
- DA virtual IPsec interface is automatically created after the Phase 1 configuration is completed.
How the community answered
(37 responses)- A5% (2)
- B3% (1)
- D92% (34)
Why each option
The question asks for a correct statement about a route-based site-to-site IPsec VPN configuration.
Firewall policies for IPsec VPNs, like other policies, are evaluated in order, but there's no requirement for them to be at the top of the list; their placement depends on the overall policy hierarchy.
Route-based VPNs are highly suitable for hub-and-spoke topologies because they allow for routing protocols to exchange routes over the VPN tunnels, simplifying network management.
In route-based IPsec VPNs, routes to remote subnets are not automatically created based on quick mode (Phase 2) selectors; instead, static routes or dynamic routing protocols must be manually configured to direct traffic through the virtual IPsec interface.
In a route-based IPsec VPN configuration on FortiGate, completing the Phase 1 configuration automatically creates a virtual IPsec tunnel interface, which serves as the logical endpoint for the VPN and is used for routing and firewall policies.
Concept tested: FortiGate route-based IPsec VPN characteristics
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/468846/route-based-vs-policy-based-ipsec-vpn
Topics
Community Discussion
No community discussion yet for this question.