nerdexam
Fortinet

NSE8_812 · Question #114

A FortiGate is used as a VPN hub for a number of remote spoke VPN units (Group A) spokes using a phase 1 main mode dial-up tunnel and pre-shared keys. You are asked to establish VPN connectivity for…

The correct answer is C. Implement a new phase 1 dial-up main mode tunnel with pre-shared keys and XAuth. D. Implement separate phase 1 dial-up aggressive mode tunnels with a distinct peer ID. See the full explanation below for the reasoning.

Question

A FortiGate is used as a VPN hub for a number of remote spoke VPN units (Group A) spokes using a phase 1 main mode dial-up tunnel and pre-shared keys. You are asked to establish VPN connectivity for a newly acquired organization's sites for which new devices will be provisioned Group B spokes. Both existing Group A and new Group B spoke units are dynamically addressed through a single public IP Address on the hub. You are asked to ensure that spokes from Group B have different access permissions than the existing VPN spokes units Group A. Which two solutions meet the requirements for the new spoke group? (Choose two.)

Options

  • AImplement a new phase 1 dial-up main mode tunnel with a different pre-shared key than the Group A spokes.
  • BImplement a new phase 1 dial-up main mode tunnel with certificate authentication.
  • CImplement a new phase 1 dial-up main mode tunnel with pre-shared keys and XAuth.
  • DImplement separate phase 1 dial-up aggressive mode tunnels with a distinct peer ID.

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    12% (4)
  • C
    82% (28)

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice