QuestionQ43

Advanced IPsec

Refer to the following exhibits.

Question Image

Question Image

Two IPsec templates, Branch_IPsec_1 and Branch_IPsec_2, are shown, and each template defines a VPN tunnel. When the administrator attempted to assign the second template to the FortiGate device, FortiManager displayed the following error message:

Question Image

Which statement best explains the cause of the issue?

  • A You can assign only one IPsec template to each FortiGate device.
  • B You should use the same outgoing interface of both templates.
  • C You can assign only one template with a tunnel type of static to each FortiGate device.
  • D You should review the branch1_fgt configuration for configured tunnels in the root VDOM.
Explanation

FortiManager treats an IPsec tunnel template as a single assignment scope on a FortiGate/VDOM. Assigning both Branch_IPsec_1 and Branch_IPsec_2 to branch1_fgt in the root VDOM therefore creates a conflicting IPsec-template assignment. The required VPN tunnels must be included in one assigned IPsec template. Fortinet documentation describes IPsec templates as assigned to devices or device groups and template groups as allowing one IPsec tunnel template.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!