nerdexam
Fortinet

NSE7 · Question #16

An administrator added the following Ipsec VPN to a FortiGate configuration: configvpn ipsec phasel -interface edit "RemoteSite" set type dynamic set interface "portl" set mode main set psksecret…

The correct answer is C. The pre-shared key is wrong. See the full explanation below for the reasoning.

Question

An administrator added the following Ipsec VPN to a FortiGate configuration:

configvpn ipsec phasel -interface edit "RemoteSite" set type dynamic set interface "portl" set mode main set psksecret ENC LCVkCiK2E2PhVUzZe next end config vpn ipsec phase2-interface edit "RemoteSite" set phasel name "RemoteSite" set proposal 3des-sha256 next end However, the phase 1 negotiation is failing. The administrator executed the IKF real time debug while attempting the Ipsec connection. The output is shown in the exhibit. What is causing the IPsec problem in the phase 1 ?

Exhibits

NSE7 question #16 exhibit 1
NSE7 question #16 exhibit 2

Options

  • AThe incoming IPsec connection is matching the wrong VPN configuration
  • BThe phrase-1 mode must be changed to aggressive
  • CThe pre-shared key is wrong
  • DNAT-T settings do not match

How the community answered

(24 responses)
  • A
    17% (4)
  • B
    8% (2)
  • C
    71% (17)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full NSE7 Practice