nerdexam
Fortinet

NSE4_FGT-6.4 · Question #151

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has…

The correct answer is A. On HQ-FortiGate, set IKE mode to Main (ID protection). B. On both FortiGate devices, set Dead Peer Detection to On Demand. See the full explanation below for the reasoning.

Question

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre- shared key on both FortiGate devices to make sure they match. Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)

Exhibit

NSE4_FGT-6.4 question #151 exhibit

Options

  • AOn HQ-FortiGate, set IKE mode to Main (ID protection).
  • BOn both FortiGate devices, set Dead Peer Detection to On Demand.
  • COn HQ-FortiGate, disable Diffie-Helman group 2.
  • DOn Remote-FortiGate, set port2 as Interface.

How the community answered

(30 responses)
  • A
    70% (21)
  • C
    10% (3)
  • D
    20% (6)

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT-6.4 Practice