QuestionQ29

VPN

You are configuring ADVPN and want to make sure that peer IDs are not revealed during VPN establishment.

Which protocol can the administrator use to improve security?

  • A Use SSL VPN tunnel mode with certificates.
  • B Use IKEv2, which encrypts peer IDs and prevents exposure.
  • C Use IKEv1 aggressive mode with certificates.
  • D Use IKEv1 main mode with AES-GCM security proposal.
Explanation

IKEv2 encrypts identity information during the protected IKE_AUTH exchange, so peer IDs are not exposed during VPN establishment. Fortinet also documents that IKEv1 aggressive mode exchanges unencrypted authentication information, and that AES-GCM phase 1 proposals are available only with IKEv2.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!