QuestionQ61

VPN

During the most recent network migration, the IT department found that every zero phase selector in phase 2 IPsec configurations affects network operations.

What two valid recommendations can prevent potential invalid paths in future migrations?

Choose two
  • A Configure an IP address on the IPsec interface of each firewall to establish unique peer connections and avoid impacting network operations.
  • B Configure the VPN with the exact segments that will be encrypted in the phase two selectors.
  • C Configure an IPsec aggregate to create redundancy between each firewall peer.
  • D Configure routing protocols to specify allowed subnets over the tunnel.
Explanation

Phase 2 selectors should define the precise local and remote segments to be encrypted, rather than using 0.0.0.0/0 selectors that match all networks. Routing must also be limited to the authorized subnets across the tunnel so that unintended or invalid destinations are not selected as VPN paths. Fortinet documents that phase 2 selectors restrict tunnel traffic to the configured local and remote subnets.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!