nerdexam
Fortinet

NSE4 · Question #372

Which of the following IPsec configuration modes can be used for implementing L2TP- over- IPSec VPNs?

The correct answer is A. Policy-based IPsec only. L2TP-over-IPSec VPNs can only be implemented using policy-based IPsec configurations, as route-based IPsec is not designed for tunnel mode with L2TP.

Submitted by fernanda_arg· Apr 18, 2026VPN and Routing

Question

Which of the following IPsec configuration modes can be used for implementing L2TP- over- IPSec VPNs?

Options

  • APolicy-based IPsec only.
  • BRoute-based IPsec only.
  • CBoth policy-based and route-based VPN.
  • DL2TP-over-IPSec is not supported by FortiGate devices.

How the community answered

(22 responses)
  • A
    91% (20)
  • B
    5% (1)
  • D
    5% (1)

Why each option

L2TP-over-IPSec VPNs can only be implemented using policy-based IPsec configurations, as route-based IPsec is not designed for tunnel mode with L2TP.

APolicy-based IPsec only.Correct

L2TP-over-IPSec VPNs are implemented using policy-based IPsec, where the FortiGate applies policies to specific traffic based on source, destination, and service, rather than routing traffic through a dedicated tunnel interface.

BRoute-based IPsec only.

Route-based IPsec creates a virtual tunnel interface and routes traffic through it, which is not the mechanism used for L2TP-over-IPSec VPNs.

CBoth policy-based and route-based VPN.

L2TP-over-IPSec VPNs specifically utilize policy-based IPsec and cannot be implemented with route-based IPsec.

DL2TP-over-IPSec is not supported by FortiGate devices.

L2TP-over-IPSec is fully supported by FortiGate devices, using policy-based IPsec.

Concept tested: IPsec modes for L2TP-over-IPSec

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/500078/vpn-settings

Topics

#IPsec modes#L2TP-over-IPSec#VPNs#Policy-based IPsec

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice