ExamGecko
Question list
Search
Search

Question 26 - NSE7_NST-7.2 discussion

Report
Export

There are four exchanges during IKEv2 negotiation.

Which sequence is correct?

A.
IKE_Proposal, ID_Auth, PiggyBack_CHILD and Informational
Answers
A.
IKE_Proposal, ID_Auth, PiggyBack_CHILD and Informational
B.
lnit_Req, Wait_lnit_Req, ID_Auth_Req and Create_CHILD_SA
Answers
B.
lnit_Req, Wait_lnit_Req, ID_Auth_Req and Create_CHILD_SA
C.
INIT_Re, INIT_Auth, ID_Child and SET_Nonce
Answers
C.
INIT_Re, INIT_Auth, ID_Child and SET_Nonce
D.
IKE_SAJNIT, IKE_Auth, Create_CHILD_SA and Informational
Answers
D.
IKE_SAJNIT, IKE_Auth, Create_CHILD_SA and Informational
Suggested answer: D

Explanation:

IKE_SA_INIT:

This is the first exchange in IKEv2. It establishes a secure, authenticated channel between peers and negotiates cryptographic algorithms and keys.

IKE_Auth:

The second exchange authenticates the IKE SA (Security Association) using the previously negotiated keys and algorithms. This exchange also establishes the first IPsec SA.

Create_CHILD_SA:

This exchange creates additional IPsec SAs after the initial authentication. It can also be used to rekey existing IPsec SAs to maintain security.

Informational:

This is a generic exchange used for various purposes such as error notification, deletion of SAs, and other control messages.

Fortinet Community: IKEv2 packet exchanges and troubleshooting

Fortinet Documentation: IPsec VPN Concepts

asked 18/09/2024
Nelson Alvaro
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first