View all questions & answers for the NSE 4 - FortiOS 7.6 Administrator Exam Materials exam


NSE 4 - FortiOS 7.6 Administrator Exam Materials-Question 31 Discussion
Comment Image Comment Image Comment Image

Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two answers)

  • A. On BR1-FGT, set Seconds to 43200.
  • B. On HQ-NGFW, enable Diffie-Hellman Group 2.
  • C. On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0.
  • D. On HQ-NGFW, set Encryption to AES256.
Correct Answer: C,D

Brave-Dump Clients Votes

CD 66.67%
C 16.67%
AD 16.67%

Comments



Alex 2025-06-25 16:20:09

Selected Answers: C


This requires two answers rather than one. C & D
  • Brave-Dumps.com Admin 2025-07-09 23:06:14
    Thanks Alex, Done.


Anonymous User 2026-01-27 04:50:30

Selected Answers: C, D


Look closely at the IP address


abdulrahman 2026-03-15 10:27:44

Selected Answers: C, D


although the correct answer is C and D. these option are not enough to make the phase up. because the DH groups must match on both ends.
  • Genco 2026-06-30 13:24:00
    They don't have to be identical but at least they should have one DH group match and in this case DH 5 groups match.
  • Genco 2026-06-30 13:24:11
    They don't have to be identical but at least they should have one DH group match and in this case DH 5 groups match.


Anonymous User 2026-03-28 15:13:59

Selected Answers: C, D


C D


Julio Ricardo Inostroza Rivas 2026-07-03 03:23:30

Selected Answers: A, D


the correct is A y D
the A) because the keepalive of IPsec SA must be the same value for both peer
the D) because for IPSec SA (Phase 2) the encryptation and authentication must be the same value too for both peers.


Ahmed El Hasseen El Tom El Shaikh Berair 2026-07-14 09:46:24

Selected Answers: C, D


31