nerdexam
Fortinet

NSE4 · Question #383

Which of the following statements are correct concerning IKE mode config? (Choose two)

The correct answer is A. It can dynamically assign IP addresses to IPsec VPN clients. B. It can dynamically assign DNS settings to IPsec VPN clients. IKE Mode Config enables the FortiGate to dynamically assign IP addresses and DNS server settings to IPsec VPN clients during tunnel establishment.

Submitted by kwame.gh· Apr 18, 2026VPN and Routing

Question

Which of the following statements are correct concerning IKE mode config? (Choose two)

Options

  • AIt can dynamically assign IP addresses to IPsec VPN clients.
  • BIt can dynamically assign DNS settings to IPsec VPN clients.
  • CIt uses the ESP protocol.
  • DIt can be enabled in the phase 2 configuration.

How the community answered

(47 responses)
  • A
    87% (41)
  • C
    4% (2)
  • D
    9% (4)

Why each option

IKE Mode Config enables the FortiGate to dynamically assign IP addresses and DNS server settings to IPsec VPN clients during tunnel establishment.

AIt can dynamically assign IP addresses to IPsec VPN clients.Correct

IKE Mode Config is a crucial feature within the Internet Key Exchange protocol that allows the FortiGate VPN gateway to dynamically allocate IP addresses from a predefined pool to connecting IPsec VPN clients, simplifying client network configuration.

BIt can dynamically assign DNS settings to IPsec VPN clients.Correct

Utilizing IKE Mode Config, the FortiGate can also dynamically push other network parameters, such as DNS server IP addresses, to the IPsec VPN clients, ensuring proper name resolution and network access for remote users.

CIt uses the ESP protocol.

IKE (Internet Key Exchange) is a control plane protocol for establishing and managing IPsec Security Associations, while ESP (Encapsulating Security Payload) is a data plane protocol used for encrypting and authenticating user data; IKE Mode Config is part of IKE, not ESP.

DIt can be enabled in the phase 2 configuration.

IKE Mode Config is negotiated during Phase 1 of the IKE process, where the control channel and client parameters are established, not during Phase 2, which focuses on setting up the IPsec Security Association for data transfer.

Concept tested: IKE Mode Config for IPsec VPN clients

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/119934/ipsec-vpn

Topics

#IKE Mode Config#IPsec VPN#VPN Client Configuration#Dynamic IP Assignment

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice