exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 98 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 98
Topic #: 1
[All NSE4_FGT-7.0 Questions]

What is the effect of enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel?

  • A. FortiGate automatically negotiates different local and remote addresses with the remote peer.
  • B. FortiGate automatically negotiates a new security association after the existing security association expires.
  • C. FortiGate automatically brings up the IPsec tunnel and keeps it up, regardless of activity on the IPsec tunnel.
  • D. FortiGate automatically negotiates different encryption and authentication algorithms with the remote peer.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Febrian
Highly Voted 1 year, 4 months ago
I think it's C. Enable auto-negotiate by default enabling auto-keep-alive too which brings up tunnel automatically. Ans B is little bit tricky, auto-negotiate will negotiate new SA "before" existing SA expired not "after" existing SA expired.
upvoted 14 times
...
Mahant55
Most Recent 3 months, 1 week ago
Selected Answer: C
Answer B suggest that after the SA expires, however incase of auto-negotiate setting negotiation happen well before the existing SA expires.
upvoted 2 times
...
mefisto100
4 months ago
Selected Answer: B
It's B: Fortigate Infraestructure 7.2 page 264 When IPsec SAs expire, FortiGate needs to negotiate new SAs to continue sending and receiving traffic over the IPsec tunnel. Technically, FortiGate deletes the expired SAs from the respective phase 2 selectors, and installs new ones. If IPsec SA renegotiation takes too much time, then FortiGate might drop interesting traffic because of the absence of active SAs. To prevent this, you can enable Auto-negotiate. When you do this, FortiGate not only negotiates new SAs before the current SAs expire, but it also starts using the new SAs right away. The latter prevents traffic disruption by IPsec SA renegotiation.
upvoted 1 times
mefisto100
4 months ago
Sorry, It's C
upvoted 1 times
...
...
FenXXX
9 months, 3 weeks ago
Selected Answer: B
It's B: FortiGate automatically negotiates a new security association after the existing security association expires. The answer would have been C if the 'Autokey Keep Alive' had been activated in addition.
upvoted 1 times
...
Besttool
9 months, 4 weeks ago
Selected Answer: C
C is the correct
upvoted 1 times
...
alexeid72
11 months, 3 weeks ago
Auto-negotiate: Enable the option to automatically renegotiate the tunnel when the tunnel expires.
upvoted 1 times
...
chyeahhh
1 year ago
Selected Answer: C
Page 222 of Infrastructure 7.0: Auto-negotiate being enabled negotiates new SAs BEFORE current SAs fail. Enabling Auto-negotiate allows the tunnel to come up and stay up automatically, even when there is no interesting traffic.
upvoted 1 times
...
DID123
1 year ago
Selected Answer: C
C is correct, B is wrong as negotiation happen before not after the current SA expire.
upvoted 1 times
...
PabloSL
1 year, 1 month ago
C according to the study guide, as the new SA is created BEFORE the old one expires
upvoted 1 times
...
root69
1 year, 1 month ago
Selected Answer: C
It's C Auto-negotiate: Enable the option to automatically renegotiate the tunnel when the tunnel expires. By default, the phase 2 security association (SA) is not negotiated until a peer attempts to send data. The triggering packet and some subsequent packets are dropped until the SA is established. Applications normally resend this data, so there is no loss, but there might be a noticeable delay in response to the user. If the tunnel goes down, the auto-negotiate feature (when enabled) attempts to re-establish the tunnel. Auto-negotiate initiates the phase-2 SA negotiation automatically, repeating every five seconds until the SA is established. Automatically establishing the SA can be important for a dial-up peer. It ensures that the VPN tunnel is available for peers at the server end to initiate traffic to the dial-up peer. Otherwise, the VPN tunnel does not exist until the dial-up peer initiates traffic.
upvoted 2 times
...
leiflo
1 year, 2 months ago
Answer is B. Reference: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-IPSec-auto-negotiate-and-keepalive/ta-p/189536
upvoted 1 times
...
Dumps345
1 year, 2 months ago
Answer is C Another benefit of enabling Auto-negotiate is that the tunnel comes up and stays up automatically, even when there is no interesting traffic. When you enable Autokey Keep Alive and keep Auto-negotiate disabled, the tunnel does not come up automatically unless there is interesting traffic. FortiGate Infrastructure 7.0 Study Guide pag 222
upvoted 1 times
...
nomeursy
1 year, 3 months ago
Selected Answer: C
Answer C is correct
upvoted 3 times
...
Kutchek
1 year, 3 months ago
Selected Answer: C
"If IPsec SA renegotiation takes too much time, then FortiGate might drop interesting traffic because of the absence of active SAs. To prevent this, you can enable Auto-negotiate. When you do this, FortiGate not only negotiates new SAs before the current SAs expire, but it also starts using the new SAs right away. The latter prevents traffic disruption by IPsec SA renegotiation. Another benefit of enabling Auto-negotiate is that the tunnel comes up and stays up automatically, even when there is no interesting traffic. " Fortigate Infrastructure Study Guide v7.0, Page 236
upvoted 1 times
...
Mahesh3012
1 year, 3 months ago
Answer is C Look in section Autonegotiate https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-the-IPSec-auto-negotiate-and-keepalive/ta-p/189536
upvoted 1 times
...
Power_Shell
1 year, 4 months ago
Selected Answer: C
AutoNegotiate renegotiates new SAs before the current SAs expire and the tunnel comes up and stays up automatically even when there is no interesting traffic.
upvoted 3 times
...
Kimkeezai
1 year, 4 months ago
It's C. According to FG infra pg. 263.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago