nerdexam
Fortinet

NSE4 · Question #350

An administrator has configured a route-based IPsec VPN between two FortiGates. Which statement about this IPsec VPN configuration is true?

The correct answer is D. A virtual IPsec interface is automatically created after the phase 1 configuration is completed.. When configuring a route-based IPsec VPN on FortiGate, a virtual IPsec interface is automatically generated upon completion of the phase 1 configuration.

Submitted by krish.m· Apr 18, 2026VPN and Routing

Question

An administrator has configured a route-based IPsec VPN between two FortiGates. Which statement about this IPsec VPN configuration is true?

Options

  • AA phase 2 configuration is not required.
  • BThis VPN cannot be used as part of a hub and spoke topology.
  • CThe IPsec firewall policies must be placed at the top of the list.
  • DA virtual IPsec interface is automatically created after the phase 1 configuration is completed.

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    92% (24)

Why each option

When configuring a route-based IPsec VPN on FortiGate, a virtual IPsec interface is automatically generated upon completion of the phase 1 configuration.

AA phase 2 configuration is not required.

Both Phase 1 (IKE Security Association) and Phase 2 (IPsec Security Association) configurations are essential and required components for establishing and maintaining any IPsec VPN tunnel.

BThis VPN cannot be used as part of a hub and spoke topology.

Route-based IPsec VPNs are highly suitable and frequently used for hub-and-spoke topologies, as they allow for flexible routing and dynamic tunnel management.

CThe IPsec firewall policies must be placed at the top of the list.

The placement of IPsec firewall policies in the policy list follows the standard FortiGate policy evaluation order, based on matching criteria, and they do not inherently need to be at the top.

DA virtual IPsec interface is automatically created after the phase 1 configuration is completed.Correct

For route-based IPsec VPNs, completing the Phase 1 configuration automatically creates a virtual IPsec interface, which acts as a logical network interface that can be used in routing tables and firewall policies.

Concept tested: FortiGate route-based IPsec VPN

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/920038/route-based-ipsec-vpn

Topics

#IPsec VPN#Route-based VPN#Virtual Interface#FortiGate Configuration

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice