ExamGecko
Question list
Search
Search

Question 36 - NSE7_NST-7.2 discussion

Report
Export

Exhibit.

Refer to the exhibit, which contains partial output from an IKE real-time debug.

The administrator does not have access to the remote gateway.

Based on the debug output, which configuration change can the administrator make to the local gateway to resolve the phase 1 negotiation error?

A.
In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
Answers
A.
In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.
B.
In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
Answers
B.
In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.
C.
In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.
Answers
C.
In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.
D.
In the phase 1 network configuration, set the IKE version to 2.
Answers
D.
In the phase 1 network configuration, set the IKE version to 2.
Suggested answer: B

Explanation:

Analyzing Debug Output:

The debug output shows multiple proposals with encryption algorithms like AES CBC and hashing algorithms like SHA256.

The negotiation failure (no SA proposal chosen) suggests that there is a mismatch in the encryption or hashing algorithms between the local and remote gateways.

Configuration Change:

To resolve the phase 1 negotiation error, the local gateway needs to include a compatible proposal.

Adding AES256-SHA256 to the phase 1 proposal configuration ensures that both gateways have a matching set of encryption and hashing algorithms.

Fortinet Documentation: Configuring IPsec Tunnels (Fortinet Docs) (Welcome to the Fortinet Community!).

Fortinet Community: Troubleshooting IKE Negotiation Failures (Welcome to the Fortinet Community!) (Welcome to the Fortinet Community!).

asked 18/09/2024
Ismaiel Al-Mufleh
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first