Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.
Based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up?
- On HQ-FortiGate, enable Auto-negotiate.
- On HQ-FortiGate, enable Diffie-Hellman Group 2.
- On HQ-FortiGate, set Encryption to AES256.
- On Remote-FortiGate, set Seconds to 43200.
Answer(s): C
Explanation:
Encryption and authentication algorithm needs to match in order for IPSEC be successfully established.
Reveal Solution Next Question