ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 38 - FCP_FGT_AD-7.4 discussion

Report
Export

Refer to the exhibit.

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.

Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)

A.
On HQ-FortiGate, disable Diffie-Helman group 2.
Answers
A.
On HQ-FortiGate, disable Diffie-Helman group 2.
B.
On Remote-FortiGate, set port2 as Interface.
Answers
B.
On Remote-FortiGate, set port2 as Interface.
C.
On both FortiGate devices, set Dead Peer Detection to On Demand.
Answers
C.
On both FortiGate devices, set Dead Peer Detection to On Demand.
D.
On HQ-FortiGate, set IKE mode to Main (ID protection).
Answers
D.
On HQ-FortiGate, set IKE mode to Main (ID protection).
Suggested answer: C, D

Explanation:

To bring Phase 1 up, the following changes can be made:A . On HQ-FortiGate, disable Diffie-Helman group 2: This is incorrect because Diffie-Hellmangroup 2 is already selected on both devices. Disabling it would not help.B . On Remote-FortiGate, set port2 as Interface: This is incorrect as both sides should beconsistent in their interface settings for the IPsec tunnel, and the interface is correctly set toport1 on both FortiGates in the IPsec configuration.C . On both FortiGate devices, set Dead Peer Detection to On Demand: This is a valid option.Setting Dead Peer Detection (DPD) to 'On Demand' helps maintain the IPsec connection bychecking if the peer is still available, which can help in some cases where the connection failsdue to timeouts.D . On HQ-FortiGate, set IKE mode to Main (ID protection): This is also a valid option becausethe Remote-FortiGate is already set to Main mode (ID protection). Ensuring that both ends usethe same mode is crucial for successful phase 1 negotiation.Thus, the correct answers are: C . On both FortiGate devices, set Dead Peer Detection to OnDemand. D . On HQ-FortiGate, set IKE mode to Main (ID protection).

asked 18/09/2024
Jesus Ignacio Morales Vivancos
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first