ExamGecko
Question list
Search
Search

Question 31 - NSE7_NST-7.2 discussion

Report
Export

Which statement about IKE and IKE NAT-T is true?

A.
IKE is used to encapsulate ESP traffic in some situations, and IKE NAT-T is used only when the local FortiGate is using NAT on the IPsec interface.
Answers
A.
IKE is used to encapsulate ESP traffic in some situations, and IKE NAT-T is used only when the local FortiGate is using NAT on the IPsec interface.
B.
IKE is the standard implementation for IKEv1 and IKE NAT-T is an extension added in IKEv2.
Answers
B.
IKE is the standard implementation for IKEv1 and IKE NAT-T is an extension added in IKEv2.
C.
They each use their own IP protocol number.
Answers
C.
They each use their own IP protocol number.
D.
They both use UDP as their transport protocol and the port number is configurable.
Answers
D.
They both use UDP as their transport protocol and the port number is configurable.
Suggested answer: D

Explanation:

IKE (Internet Key Exchange): IKE is a protocol used to set up a security association (SA) in the IPsec protocol suite. It is utilized to negotiate, create, and manage SAs.

NAT-T (Network Address Translation-Traversal): NAT-T is used to enable IPsec VPN traffic to pass through NAT devices. It encapsulates IPsec ESP packets into UDP packets.

Transport Protocol: Both IKE and IKE NAT-T use UDP as their transport protocol.

Port Numbers: By default, IKE uses UDP port 500. NAT-T typically uses UDP port 4500. However, these port numbers can be configured as needed.

Fortinet Network Security Support Engineer Study Guide for FortiOS 7.2 (Fortinet Docs) (ebin.pub).

Fortinet Documentation on IPsec VPN Configuration (Fortinet Docs).

asked 18/09/2024
Dasaret Tillman
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first