Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 7 - Enterprise Firewall Administrator

Domain 5Objective 1

Implement IPsec VPN IKE Version 2 NSE7-ENTERPRISE-FIREWALL-ADMINISTRATOR Practice Questions (Page 3)

Part of the VPN domain, which makes up ~7% of our current practice bank. Fortinet does not publish an official question count, but from its 70-minute exam (~30–45 total, ~2–3 in this domain), expect 1–2 from this objective — we provide 13 practice questions to prepare you well beyond it. (estimate)

13questions here
3free pages
5concepts

Questions 11–13

  1. 11foundation · easy

    In an IKEv2 negotiation, which role does the device that sends the first IKE_SA_INIT message assume?

    Select an answer first
  2. 12application · medium

    A network engineer is configuring a site-to-site IPsec VPN between two FortiGates using IKEv2. The remote FortiGate is behind a NAT device that does not support IPsec NAT-T. During testing, the IKE_SA_INIT exchange fails. The engineer checks the IKE debug logs and sees that the responder is not sending any response to the initiator's initial packet. Which action should the engineer take to resolve this issue?

    Select an answer first
  3. 13application · medium

    An administrator is troubleshooting an IKEv2 VPN that fails to establish. The administrator runs 'diagnose vpn ike log' and sees the following message: 'IKE_AUTH: authentication failed'. The Phase 1 configuration uses pre-shared keys. What is the most likely cause of this failure?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE7-ENTERPRISE-FIREWALL-ADMINISTRATOR” is a trademark of its owner, used for identification only.