List of questions
Related questions
Question 38 - FCP_FGT_AD-7.4 discussion
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)
A.
On HQ-FortiGate, disable Diffie-Helman group 2.
B.
On Remote-FortiGate, set port2 as Interface.
C.
On both FortiGate devices, set Dead Peer Detection to On Demand.
D.
On HQ-FortiGate, set IKE mode to Main (ID protection).
Your answer:
0 comments
Sorted by
Leave a comment first