nerdexam
Fortinet

NSE7 · Question #16

NSE7 Question #16: Real Exam Question with Answer & Explanation

Sign in or unlock NSE7 to reveal the answer and full explanation for question #16. The question stem and answer options stay visible for context.

Question

An administrator added the following Ipsec VPN to a FortiGate configuration: configvpn ipsec phasel -interface edit "RemoteSite" set type dynamic set interface "portl" set mode main set psksecret ENC LCVkCiK2E2PhVUzZe next end config vpn ipsec phase2-interface edit "RemoteSite" set phasel name "RemoteSite" set proposal 3des-sha256 next end However, the phase 1 negotiation is failing. The administrator executed the IKF real time debug while attempting the Ipsec connection. The output is shown in the exhibit. What is causing the IPsec problem in the phase 1 ?

Exhibits

NSE7 question #16 exhibit 1
NSE7 question #16 exhibit 2

Options

  • AThe incoming IPsec connection is matching the wrong VPN configuration
  • BThe phrase-1 mode must be changed to aggressive
  • CThe pre-shared key is wrong
  • DNAT-T settings do not match

Unlock NSE7 to see the answer

You've previewed enough free NSE7 questions. Unlock NSE7 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full NSE7 Practice