nerdexam
Fortinet

NSE4 · Question #359

Which statements about an IPv6-over-IPv4 IPsec configuration are correct? (Choose two.)

The correct answer is C. The local gateway IP must an IPv4 address. D. The destination quick mode selector must be an IPv6 address. In an IPv6-over-IPv4 IPsec configuration, the local and remote gateways use IPv4 addresses to establish the tunnel, while the traffic being secured and tunneled (quick mode selectors) is IPv6.

Submitted by sofia.br· Apr 18, 2026VPN and Routing

Question

Which statements about an IPv6-over-IPv4 IPsec configuration are correct? (Choose two.)

Options

  • AThe remote gateway IP must be an IPv6 address.
  • BThe source quick mode selector must be an IPv4 address.
  • CThe local gateway IP must an IPv4 address.
  • DThe destination quick mode selector must be an IPv6 address.

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    17% (4)
  • C
    75% (18)

Why each option

In an IPv6-over-IPv4 IPsec configuration, the local and remote gateways use IPv4 addresses to establish the tunnel, while the traffic being secured and tunneled (quick mode selectors) is IPv6.

AThe remote gateway IP must be an IPv6 address.

The remote gateway IP must be an IPv4 address because the tunnel is built over an IPv4 network, carrying IPv6 traffic.

BThe source quick mode selector must be an IPv4 address.

The source quick mode selector defines the source of the traffic being encapsulated, which in an IPv6-over-IPv4 tunnel is IPv6 traffic.

CThe local gateway IP must an IPv4 address.Correct

Since the tunnel is 'IPv6-over-IPv4', the underlying IPsec tunnel endpoints (gateways) are established using IPv4 addresses. Thus, the local gateway IP must be an IPv4 address.

DThe destination quick mode selector must be an IPv6 address.Correct

The purpose of an IPv6-over-IPv4 IPsec tunnel is to securely transport IPv6 traffic. Therefore, the destination quick mode selector, which defines the encapsulated traffic, must be an IPv6 address.

Concept tested: IPv6-over-IPv4 IPsec tunnel configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/25390/ipv6-ipsec-vpn

Topics

#IPsec VPN#IPv6 over IPv4#VPN Configuration#Quick Mode Selectors

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice