ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 21 - FCSS_SASE_AD-23 discussion

Report
Export

Refer to the exhibits.

A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish

Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?

A.
NAT needs to be enabled in the Spoke-to-Hub firewall policy.
Answers
A.
NAT needs to be enabled in the Spoke-to-Hub firewall policy.
B.
The BGP router ID needs to match on the hub and FortiSASE.
Answers
B.
The BGP router ID needs to match on the hub and FortiSASE.
C.
FortiSASE spoke devices do not support mode config.
Answers
C.
FortiSASE spoke devices do not support mode config.
D.
The hub needs IKEv2 enabled in the IPsec phase 1 settings.
Answers
D.
The hub needs IKEv2 enabled in the IPsec phase 1 settings.
Suggested answer: C

Explanation:

The VPN tunnel between the FortiSASE spoke and the FortiGate hub is not establishing due to the configuration of mode config, which is not supported by FortiSASE spoke devices. Mode config is used to assign IP addresses to VPN clients dynamically, but this feature is not applicable to FortiSASE spokes.

Mode Config in IPsec:

The configuration snippet shows that mode config is enabled in the IPsec phase 1 settings.

Mode config is typically used for VPN clients to dynamically receive an IP address from the VPN server, but it is not suitable for site-to-site VPN configurations involving FortiSASE spokes.

Configuration Adjustment:

To establish the VPN tunnel, you need to disable mode config in the IPsec phase 1 settings.

This adjustment will allow the FortiSASE spoke to properly establish the VPN tunnel with the FortiGate hub.

Steps to Disable Mode Config:

Access the VPN configuration on the FortiSASE spoke.

Edit the IPsec phase 1 settings to disable mode config.

Ensure other settings such as pre-shared key, remote gateway, and BGP configurations are correct and consistent with the FortiGate hub.

FortiOS 7.2 Administration Guide: Provides details on configuring IPsec VPNs and mode config settings.

FortiSASE 23.2 Documentation: Explains the supported configurations for FortiSASE spoke devices and VPN setups.

asked 18/09/2024
Daniela Const
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first