nerdexam
Fortinet

NSE4 · Question #38

Review the static route configuration for IPsec shown in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)

The correct answer is A. Interface remote is an IPsec interface. B. A gateway address is not required because the interface is a point-to-point connection. When configuring a static route for IPsec on a FortiGate, if the outgoing interface is an IPsec tunnel interface, a gateway address is not required because the tunnel itself represents a point-to-point connection.

Submitted by weili_xi· Apr 18, 2026VPN and Routing

Question

Review the static route configuration for IPsec shown in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)

Exhibit

NSE4 question #38 exhibit

Options

  • AInterface remote is an IPsec interface.
  • BA gateway address is not required because the interface is a point-to-point connection.
  • CA gateway address is not required because the default route is used.
  • DInterface remote is a zone.

How the community answered

(46 responses)
  • A
    91% (42)
  • C
    2% (1)
  • D
    7% (3)

Why each option

When configuring a static route for IPsec on a FortiGate, if the outgoing interface is an IPsec tunnel interface, a gateway address is not required because the tunnel itself represents a point-to-point connection.

AInterface remote is an IPsec interface.Correct

In FortiGate static route configuration, specifying a tunnel name like 'remote' (as implied by the exhibit) in the 'Device' field indicates that the traffic will be sent over an IPsec VPN tunnel, meaning 'remote' is an IPsec interface.

BA gateway address is not required because the interface is a point-to-point connection.Correct

When the outgoing interface for a static route is an IPsec tunnel interface, which is a point-to-point logical connection, the gateway address is typically omitted as the traffic is encapsulated and forwarded directly through the tunnel.

CA gateway address is not required because the default route is used.

The absence of a gateway address on a specific route does not imply that the default route is used; it indicates the specified interface acts as the direct next hop for that route.

DInterface remote is a zone.

While FortiGate supports zones, an IPsec interface is a distinct type of virtual interface representing a VPN tunnel, not a zone itself, although an IPsec interface can be part of a zone.

Concept tested: FortiGate IPsec static route configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/86958/static-route

Topics

#Static Routing#IPsec VPN (Route-based)#FortiGate Interfaces#Routing Concepts

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice