nerdexam
Fortinet

NSE4 · Question #382

Which of the following statements are correct concerning IPsec dialup VPN configurations for FortiGate devices? (Choose two)

The correct answer is C. Peer ID must be used when there is more than one aggressive-mode IPsec dialup VPN on the D. The FortiGate will automatically add a static route to the source quick mode selector address. When configuring multiple aggressive-mode IPsec dialup VPNs on a FortiGate, a unique Peer ID is required for each, and the FortiGate automatically adds a static route for the quick mode selector's destination.

Submitted by takeshi77· Apr 18, 2026VPN and Routing

Question

Which of the following statements are correct concerning IPsec dialup VPN configurations for FortiGate devices? (Choose two)

Options

  • AMain mode mist be used when there is no more than one IPsec dialup VPN configured on the
  • BA FortiGate device with an IPsec VPN configured as dialup can initiate the tunnel connection to
  • CPeer ID must be used when there is more than one aggressive-mode IPsec dialup VPN on the
  • DThe FortiGate will automatically add a static route to the source quick mode selector address

How the community answered

(56 responses)
  • A
    7% (4)
  • B
    13% (7)
  • C
    80% (45)

Why each option

When configuring multiple aggressive-mode IPsec dialup VPNs on a FortiGate, a unique Peer ID is required for each, and the FortiGate automatically adds a static route for the quick mode selector's destination.

AMain mode mist be used when there is no more than one IPsec dialup VPN configured on the

While main mode offers enhanced security and is often preferred for site-to-site VPNs, aggressive mode is commonly used for dial-up VPNs regardless of the number of tunnels due to its faster negotiation, and its use is not strictly limited by the count of VPNs.

BA FortiGate device with an IPsec VPN configured as dialup can initiate the tunnel connection to

A FortiGate device configured as an IPsec dialup VPN server acts as a listener and waits for remote clients to initiate the tunnel connection; it cannot initiate a dialup connection itself.

CPeer ID must be used when there is more than one aggressive-mode IPsec dialup VPN on theCorrect

When configuring multiple aggressive-mode IPsec dialup VPNs on a FortiGate, a unique Peer ID is essential for the FortiGate to correctly distinguish and apply the appropriate tunnel configuration for each connecting client.

DThe FortiGate will automatically add a static route to the source quick mode selector addressCorrect

Upon successful establishment of an IPsec dialup VPN tunnel, the FortiGate automatically adds a static route for the remote client's network (defined by the quick mode selector's destination address) through the VPN interface, simplifying routing management.

Concept tested: FortiGate IPsec dialup VPN configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/119934/ipsec-vpn

Topics

#IPsec VPN#Dialup VPN#Aggressive Mode#Peer ID

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice