nerdexam
Fortinet

NSE5_FAZ-7.2 · Question #31

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)

The correct answer is B. Must establish an IPsec tunnel ID and pre-shared key. D. IPsec is only enabled through the CLI on FortiAnalyzer. IPsec requires a unique tunnel ID and a pre-shared key to authenticate and encrypt data between the FortiAnalyzer and FortiGate. While the FortiGate may have some configuration options related to IPsec, the primary configuration and enabling of the tunnel are done through the…

FortiAnalyzer Deployment

Question

Which statements are true regarding securing communications between FortiAnalyzer and FortiGate with IPsec? (Choose two.)

Options

  • AMust configure the FortiAnalyzer end of the tunnel only--the FortiGate end is auto-negotiated.
  • BMust establish an IPsec tunnel ID and pre-shared key.
  • CIPsec cannot be enabled if SSL is enabled as well.
  • DIPsec is only enabled through the CLI on FortiAnalyzer.

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    84% (36)
  • C
    9% (4)

Explanation

IPsec requires a unique tunnel ID and a pre-shared key to authenticate and encrypt data between the FortiAnalyzer and FortiGate. While the FortiGate may have some configuration options related to IPsec, the primary configuration and enabling of the tunnel are done through the FortiAnalyzer's CLI.

Topics

#IPsec#secure communications#FortiGate integration#CLI configuration

Community Discussion

No community discussion yet for this question.

Full NSE5_FAZ-7.2 Practice