Fortinet
NSE4_FGT-6.4 · Question #151
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has…
The correct answer is A. On HQ-FortiGate, set IKE mode to Main (ID protection). B. On both FortiGate devices, set Dead Peer Detection to On Demand. See the full explanation below for the reasoning.
Question
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre- shared key on both FortiGate devices to make sure they match. Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
Exhibit
Options
- AOn HQ-FortiGate, set IKE mode to Main (ID protection).
- BOn both FortiGate devices, set Dead Peer Detection to On Demand.
- COn HQ-FortiGate, disable Diffie-Helman group 2.
- DOn Remote-FortiGate, set port2 as Interface.
How the community answered
(30 responses)- A70% (21)
- C10% (3)
- D20% (6)
Community Discussion
No community discussion yet for this question.
