nerdexam
Fortinet

NSE7_SDW-6.4 · Question #26

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN. What two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to…

The correct answer is A. Specify a unique peer ID for each dial-up VPN interface. See the full explanation below for the reasoning.

Question

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN. What two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

Options

  • ASpecify a unique peer ID for each dial-up VPN interface.
  • BUse dial-up communities are used between the interfaces.
  • CConfigure the IKE mode to be aggressive mode.
  • DUse unique Diffie Hellman groups on each VPN interface.

How the community answered

(28 responses)
  • A
    75% (21)
  • B
    7% (2)
  • C
    14% (4)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full NSE7_SDW-6.4 Practice