Fortinet Fortigate Administrator FCP Fortigate 76 · Free Practice Question Medium
Question 6
Which of the following are purposes of NAT traversal in IPsec? (Choose two.)
-
A
A. To detect intermediary NAT devices in the tunnel path.
-
B
B. To dynamically change phase 1 negotiation mode aggressive mode.
-
C
C. To encapsulation ESP packets in UDP packets using port 4500.
-
D
D. To force a new DH exchange with each phase 2 rekey
Reveal correct answers
Correct answers: A, C
Explanation
Correct answer: AC
When NAT-T is enabled on both ends, peers can detect any NAT device along the path. If NAT is found, then the following occurs:
- Both phase 2 and remaining phase 1 packets change to UDP port 4500.
- Both ends encapsulate ESP within UDP port 4500.
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD48755
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
