nerdexam
Fortinet

NSE4_FGT_AD-7.6 · Question #94

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the…

The correct answer is A. On HQ-FortiGate, set IKE mode to Main (ID protection). B. On Remote-FortiGate, set port2 as Interface. You've hit your limit · resets 5am (America/New_York)

VPN

Question

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match. Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)

Options

  • AOn HQ-FortiGate, set IKE mode to Main (ID protection).
  • BOn Remote-FortiGate, set port2 as Interface.
  • COn HQ-FortiGate, disable Diffie-Hellman group 2.
  • DOn both FortiGate devices, set Dead Peer Detection to On Demand.

How the community answered

(33 responses)
  • A
    67% (22)
  • C
    12% (4)
  • D
    21% (7)

Explanation

You've hit your limit · resets 5am (America/New_York)

Topics

#IPsec VPN#phase 1#IKE mode#DH group

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT_AD-7.6 Practice