nerdexam
Fortinet

NSE4 · Question #404

Which of the following statements are correct concerning the IPsec phase 1 and phase 2, shown in the exhibit? (choose two)

The correct answer is C. The FortiGate device will automatically add a static route to the source quick mode selector D. The configuration will work only to establish FortiClient-to-FortiGate tunnels. A FortiGate tunnel. Based on typical FortiGate IPsec configurations, the device can automatically add a static route for the VPN tunnel, and a specific setup might be intended solely for FortiClient-to-FortiGate connections.

Submitted by lars.no· Apr 18, 2026VPN and Routing

Question

Which of the following statements are correct concerning the IPsec phase 1 and phase 2, shown in the exhibit? (choose two)

Exhibit

NSE4 question #404 exhibit

Options

  • AThe quick mode selector in the remote site must also be 0.0.0.0/0 for the source and
  • BOnly remote peers with the peer ID 'fortinet' will be able to establish a VPN.
  • CThe FortiGate device will automatically add a static route to the source quick mode selector
  • DThe configuration will work only to establish FortiClient-to-FortiGate tunnels. A FortiGate tunnel

How the community answered

(16 responses)
  • A
    19% (3)
  • B
    6% (1)
  • C
    75% (12)

Why each option

Based on typical FortiGate IPsec configurations, the device can automatically add a static route for the VPN tunnel, and a specific setup might be intended solely for FortiClient-to-FortiGate connections.

AThe quick mode selector in the remote site must also be 0.0.0.0/0 for the source and

For a VPN to establish correctly, the remote site's *local* quick mode selector must match the local site's *remote* quick mode selector; they don't both universally have to be 0.0.0.0/0, especially in site-to-site scenarios.

BOnly remote peers with the peer ID 'fortinet' will be able to establish a VPN.

While a specific peer ID limits which remote peers can establish *this specific tunnel*, it does not limit the establishment of *other* VPNs or imply that only FortiGate devices can connect, as other vendors could use the same ID.

CThe FortiGate device will automatically add a static route to the source quick mode selectorCorrect

When `set add-route enable` is configured in an IPsec phase 2, the FortiGate automatically adds a static route for the protected network (defined by the quick mode selector) pointing to the VPN tunnel interface.

DThe configuration will work only to establish FortiClient-to-FortiGate tunnels. A FortiGate tunnelCorrect

A VPN configuration with broad phase 2 selectors (e.g., 0.0.0.0/0 for both source and destination) and potentially a specific peer ID often indicates a configuration designed for FortiClient dial-up VPNs, rather than site-to-site VPNs with another FortiGate.

Concept tested: FortiGate IPsec VPN configuration logic (client VPNs, route addition)

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/52678/ipsec-vpn

Topics

#IPsec VPN#Remote Access VPN#FortiClient#Routing

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice