nerdexam
Fortinet

NSE4 · Question #244

WAN optimization is configured in Active/Passive mode. When will the remote peer accept an attempt to initiate a tunnel?

The correct answer is A. The attempt will be accepted when the request comes from a known peer and there is a matching. In Active/Passive WAN optimization, a remote peer accepts a tunnel initiation only if the request comes from a known peer and there is a matching WAN optimization passive rule configured.

Submitted by brentm· Apr 18, 2026VPN and Routing

Question

WAN optimization is configured in Active/Passive mode. When will the remote peer accept an attempt to initiate a tunnel?

Options

  • AThe attempt will be accepted when the request comes from a known peer and there is a matching
  • BThe attempt will be accepted when there is a matching WAN optimization passive rule.
  • CThe attempt will be accepted when the request comes from a known peer.
  • DThe attempt will be accepted when a user on the remote peer accepts the connection request.

How the community answered

(64 responses)
  • A
    91% (58)
  • B
    2% (1)
  • C
    3% (2)
  • D
    5% (3)

Why each option

In Active/Passive WAN optimization, a remote peer accepts a tunnel initiation only if the request comes from a known peer and there is a matching WAN optimization passive rule configured.

AThe attempt will be accepted when the request comes from a known peer and there is a matchingCorrect

In FortiGate WAN optimization configured for Active/Passive mode, for a remote peer (passive end) to accept a tunnel initiation, two conditions must be met: the initiating device must be a known peer (configured as such), and there must be a corresponding WAN optimization passive rule defined to handle the incoming traffic.

BThe attempt will be accepted when there is a matching WAN optimization passive rule.

While a matching WAN optimization passive rule is necessary, it is not sufficient; the request must also originate from a known peer for the tunnel to be accepted.

CThe attempt will be accepted when the request comes from a known peer.

While the request coming from a known peer is necessary, it is not sufficient; there must also be a matching WAN optimization passive rule to define how the traffic should be handled.

DThe attempt will be accepted when a user on the remote peer accepts the connection request.

WAN optimization tunnel initiation is an automated process between FortiGate units and does not require manual user acceptance on the remote peer.

Concept tested: FortiGate WAN optimization active/passive tunnel initiation

Source: https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/44585/wan-optimization

Topics

#WAN Optimization#Active/Passive Mode#Peer Recognition#Tunnel Establishment

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice