What port does IKE use?
What VPN topology has the simplest configuration?
Hub-and-Spoke
What are some cases in which you wouldn’t want a Hub-and-Spoke VPN topology?
What is the likely cause if an IPsec tunnel is not coming up and you get a negotiation failure error?
IPsec configuration mismatch, verify phase 1 and 2 configurations between both peers
What is the likely cause if an IPsec tunnel is unstable and you get an error saying DPD packet lost?
What must be done in the firewall policy for an IPsec tunnel to come up?
Create a policy accepting traffic on the IPsec tunnel
What setting determines whether a tunnel is used as primary or backup?
Routing
What are the two modes IPsec can operate in?
What authentication does IKEv1 support?
What authentication does IKEv2 support instead of XAuth?
EAP
What is a reason to use mesh topology over hub-and-spoke?
What are some remote gateway types in VPNs?
When would you use Dialup User?
When the remote peer IP address is unknown
What is IKE Mode Config?
What problem did NAT traversal solve?
What are keepalive probes used for?
What is the default mode of dead peer detection?
What are the two authentication methods FortiGate supports in phase 1?
What are the two negotiation modes IKE supports?
What are benefits of using route-based IPsec VPN over Policy-based?
What do you need to make your IPsec VPN deployment more resilient?
Provide a second ISP connection to your site and configure two IPsec VPNs
What are some steps needed to configure a redundant VPN?