nerdexam
Fortinet

NSE4 · Question #292

A network administrator needs to implement dynamic route redundancy between a FortiGate unit located in a remote office and a FortiGate unit located in the central office. The remote office accesses…

The correct answer is A. Use two or more route-based IPSec VPN tunnels and enable OSPF on the IPSec virtual. To implement dynamic route redundancy over multiple IPSec VPN tunnels between FortiGate units, using route-based VPNs with OSPF is the most effective method.

Submitted by valeria.br· Apr 18, 2026VPN and Routing

Question

A network administrator needs to implement dynamic route redundancy between a FortiGate unit located in a remote office and a FortiGate unit located in the central office. The remote office accesses central resources using IPSec VPN tunnels through two different Internet providers. What is the best method for allowing the remote office access to the resources through the FortiGate unit used at the central office?

Options

  • AUse two or more route-based IPSec VPN tunnels and enable OSPF on the IPSec virtual
  • BUse two or more policy-based IPSec VPN tunnels and enable OSPF on the IPSec virtual
  • CUse route-based VPNs on the central office FortiGate unit to advertise routes with a dynamic
  • DDynamic routing protocols cannot be used over IPSec VPN tunnels.

How the community answered

(19 responses)
  • A
    79% (15)
  • B
    11% (2)
  • C
    5% (1)
  • D
    5% (1)

Why each option

To implement dynamic route redundancy over multiple IPSec VPN tunnels between FortiGate units, using route-based VPNs with OSPF is the most effective method.

AUse two or more route-based IPSec VPN tunnels and enable OSPF on the IPSec virtualCorrect

Route-based IPSec VPN tunnels create virtual interfaces that dynamic routing protocols like OSPF can bind to. This allows FortiGate units to dynamically exchange routes and achieve automatic failover and load balancing across multiple VPN tunnels, providing robust redundancy.

BUse two or more policy-based IPSec VPN tunnels and enable OSPF on the IPSec virtual

Policy-based VPNs do not create virtual interfaces, making it impossible to enable dynamic routing protocols like OSPF directly over them for route advertisement and redundancy.

CUse route-based VPNs on the central office FortiGate unit to advertise routes with a dynamic

While route-based VPNs are correct, simply advertising routes with a dynamic metric using a static setup lacks the full automation and dynamic failover capabilities provided by OSPF.

DDynamic routing protocols cannot be used over IPSec VPN tunnels.

Dynamic routing protocols such as OSPF and BGP are fully supported and commonly used over route-based IPSec VPN tunnels on FortiGate devices to enhance routing flexibility and redundancy.

Concept tested: IPSec VPN route redundancy with OSPF

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469440/ipsec-with-dynamic-routing

Topics

#IPSec VPN#Route-based VPN#Dynamic Routing#Redundancy

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice