nerdexam
Fortinet

NSE4 · Question #115

In an IPSec gateway-to-gateway configuration, two FortiGate units create a VPN tunnel between two separate private networks. Which of the following configuration steps must be performed on both…

The correct answer is A. Create firewall policies to control traffic between the IP source and destination address. D. Define the Phase 2 parameters that the FortiGate unit needs to create a VPN tunnel with the E. Define the Phase 1 parameters that the FortiGate unit needs to authenticate the remote peers. IPSec gateway-to-gateway VPNs require defining Phase 1 and Phase 2 parameters on both FortiGates for tunnel establishment and creating firewall policies for traffic flow.

Submitted by obi.ng· Apr 18, 2026VPN and Routing

Question

In an IPSec gateway-to-gateway configuration, two FortiGate units create a VPN tunnel between two separate private networks. Which of the following configuration steps must be performed on both FortiGate units to support this configuration? (Select all that apply.)

Options

  • ACreate firewall policies to control traffic between the IP source and destination address.
  • BConfigure the appropriate user groups on the FortiGate units to allow users access to the IPSec
  • CSet the operating mode of the FortiGate unit to IPSec VPN mode.
  • DDefine the Phase 2 parameters that the FortiGate unit needs to create a VPN tunnel with the
  • EDefine the Phase 1 parameters that the FortiGate unit needs to authenticate the remote peers.

How the community answered

(55 responses)
  • A
    78% (43)
  • B
    7% (4)
  • C
    15% (8)

Why each option

IPSec gateway-to-gateway VPNs require defining Phase 1 and Phase 2 parameters on both FortiGates for tunnel establishment and creating firewall policies for traffic flow.

ACreate firewall policies to control traffic between the IP source and destination address.Correct

Firewall policies must be created on both FortiGate units to explicitly permit traffic to flow between the protected private networks through the IPSec VPN tunnel.

BConfigure the appropriate user groups on the FortiGate units to allow users access to the IPSec

User groups are relevant for client-to-site VPNs (e.g., remote access) where individual users authenticate, not typically for gateway-to-gateway IPSec VPNs which connect networks.

CSet the operating mode of the FortiGate unit to IPSec VPN mode.

FortiGate units operate in modes like NAT/Route or Transparent, and IPSec VPN is a feature configured within these modes, not a separate operating mode itself.

DDefine the Phase 2 parameters that the FortiGate unit needs to create a VPN tunnel with theCorrect

Phase 2 parameters, which define the security associations for the actual data transfer (encryption and integrity algorithms, key lifetimes), must be configured on both peers.

EDefine the Phase 1 parameters that the FortiGate unit needs to authenticate the remote peers.Correct

Phase 1 parameters, which define how the peers authenticate each other and establish a secure channel for exchanging Phase 2 keys, must be configured identically on both peers.

Concept tested: IPSec gateway-to-gateway configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/867946/ipsec-vpn

Topics

#IPSec VPN#Gateway-to-gateway VPN#VPN Tunnel Configuration#Firewall Policy

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice