Fortinet
NSE4_FGT_AD-7.6 · Question #94
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the…
The correct answer is A. On HQ-FortiGate, set IKE mode to Main (ID protection). B. On Remote-FortiGate, set port2 as Interface. You've hit your limit · resets 5am (America/New_York)
VPN
Question
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match. Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)
Options
- AOn HQ-FortiGate, set IKE mode to Main (ID protection).
- BOn Remote-FortiGate, set port2 as Interface.
- COn HQ-FortiGate, disable Diffie-Hellman group 2.
- DOn both FortiGate devices, set Dead Peer Detection to On Demand.
How the community answered
(33 responses)- A67% (22)
- C12% (4)
- D21% (7)
Explanation
You've hit your limit · resets 5am (America/New_York)
Topics
#IPsec VPN#phase 1#IKE mode#DH group
Community Discussion
No community discussion yet for this question.