Fortinet
NSE8_812 · Question #114
A FortiGate is used as a VPN hub for a number of remote spoke VPN units (Group A) spokes using a phase 1 main mode dial-up tunnel and pre-shared keys. You are asked to establish VPN connectivity for…
The correct answer is C. Implement a new phase 1 dial-up main mode tunnel with pre-shared keys and XAuth. D. Implement separate phase 1 dial-up aggressive mode tunnels with a distinct peer ID. See the full explanation below for the reasoning.
Question
A FortiGate is used as a VPN hub for a number of remote spoke VPN units (Group A) spokes using a phase 1 main mode dial-up tunnel and pre-shared keys. You are asked to establish VPN connectivity for a newly acquired organization's sites for which new devices will be provisioned Group B spokes. Both existing Group A and new Group B spoke units are dynamically addressed through a single public IP Address on the hub. You are asked to ensure that spokes from Group B have different access permissions than the existing VPN spokes units Group A. Which two solutions meet the requirements for the new spoke group? (Choose two.)
Options
- AImplement a new phase 1 dial-up main mode tunnel with a different pre-shared key than the Group A spokes.
- BImplement a new phase 1 dial-up main mode tunnel with certificate authentication.
- CImplement a new phase 1 dial-up main mode tunnel with pre-shared keys and XAuth.
- DImplement separate phase 1 dial-up aggressive mode tunnels with a distinct peer ID.
How the community answered
(34 responses)- A6% (2)
- B12% (4)
- C82% (28)
Community Discussion
No community discussion yet for this question.