Question 1
Question
Protocol RFC 2409 (__V1) RFC 4305 (__V2)
NAT IP protocol 17: UDP port 500 (UDP 4500 for rekey, quick mode. mode-cfg)
No NAT IP protocol 17: UDP port 500
Question 2
Question
Protocol RFC 4303
NAT IP protocol 17: UDP port 4500
No NAT IP protocol 50
Question 3
Answer
-
Internet Key Exchange
-
Internet Key Extend
-
Internet Key Expert
Question 4
Answer
-
Authentication Header
-
Authentication Helpers
Question 5
Question 6
Question
is used to authenticate peers, exchange keys, and negotiate the encryption and checksums that will be used; essentially, it is the control channel.
Question 7
Question
contains the authentieetion header—the checksums that verify the integrity of the data.
Question 8
Question
is the encapsulated security payload—the encrypted payload, essentially, the data channel.
Question 9
Question
Authentication Header (AH) does not offer encryption. So AH is not used by Fortigate.
Question 10
Question
IPsec provides services at the:
Answer
-
Network layer
-
Transport layer
-
Session layer
-
Data link layer
Question 11
Question
IPsec can operate in two modes:
Question 12
Question
directly encapsulates and protects the fourth layer (transport) and above. The original IP header is not protected and no additional lP header is added.
Answer
-
Transport mode
-
Tunnel mode
Question 13
Question
is a true tunnel. The whole lP packet is encapsulated and a new IP header is added at the beginning. After the lPsec packet reaches the remote LAN, and is unwrapped, the original packet can continue on its journey.
Answer
-
Tunnel mode
-
Transport mode
Question 14
Answer
-
Security Association
-
System Association
-
Security Access
Question 15
Question
IKE no uses phases
Question 16
Question
In which encapsulation mode is the original IP header protected?
Answer
-
A. Tunnel mode
-
B. Transport mode
Question 17
Question
Which encapsulation mode is used for end—to-end (or client-to-client) VPNS?
Answer
-
Tunnel mode
-
Transport mode