Fortinet
NSE7_SDW-6.4 · Question #26
FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN. What two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to…
The correct answer is A. Specify a unique peer ID for each dial-up VPN interface. See the full explanation below for the reasoning.
Question
FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN. What two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)
Options
- ASpecify a unique peer ID for each dial-up VPN interface.
- BUse dial-up communities are used between the interfaces.
- CConfigure the IKE mode to be aggressive mode.
- DUse unique Diffie Hellman groups on each VPN interface.
How the community answered
(28 responses)- A75% (21)
- B7% (2)
- C14% (4)
- D4% (1)
Community Discussion
No community discussion yet for this question.