Fortinet
NSE4_FGT_AD-7.6 · Question #17
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come…
The correct answer is C. On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0. D. On HQ-NGFW, set Encryption to AES256. You've hit your limit · resets 5am (America/New_York)
VPN
Question
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.)
Options
- AOn BR1-FGT, set Seconds to 43200.
- BOn HQ-NGFW, enable Diffie-Hellman Group 2.
- COn BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0.
- DOn HQ-NGFW, set Encryption to AES256.
How the community answered
(42 responses)- A12% (5)
- B19% (8)
- C69% (29)
Explanation
You've hit your limit · resets 5am (America/New_York)
Topics
#IPsec#phase 2#encryption mismatch#proxy ID
Community Discussion
No community discussion yet for this question.