ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 17 - FCP_FGT_AD-7.4 discussion

Report
Export

Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)

A.
The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN.
Answers
A.
The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN.
B.
The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
Answers
B.
The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
C.
The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
Answers
C.
The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
D.
The client FortiGate requires a manually added route to remote subnets.
Answers
D.
The client FortiGate requires a manually added route to remote subnets.
Suggested answer: B, C

Explanation:

For SSL VPN to function correctly between two FortiGate devices, the following settings arerequired:
B . The server FortiGate requires a CA certificate to verify the client FortiGate certificate: Theserver FortiGate must have a Certificate Authority (CA) certificate installed to authenticate andverify the certificate presented by the client FortiGate device.
C . The client FortiGate requires a client certificate signed by the CA on the server FortiGate:The client FortiGate must have a client certificate that is signed by the same CA that the serverFortiGate uses for verification. This ensures a secure SSL VPN connection between the twodevices.The other options are not directly necessary for establishing SSL VPN:A . The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN: This isincorrect as SSL VPN does not require a specific tunnel interface type; it typically uses an SSLVPN client profile.
D . The client FortiGate requires a manually added route to remote subnets: While routing maybe necessary, it is not specifically required for the SSL VPN functionality between twoFortiGates.ReferenceFortiOS 7.4.1 Administration Guide - Configuring SSL VPN, page 1203.FortiOS 7.4.1 Administration Guide - SSL VPN Authentication, page 1210

asked 18/09/2024
Tyler Smith
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first