nerdexam
Fortinet

NSE4 · Question #413

What is required in a FortiGate configuration to have more than one dialup IPsec VPN using aggressive mode?

The correct answer is C. Each aggressive mode dialup MUST accept connections from different peer ID. To configure multiple aggressive mode dialup IPsec VPNs on a FortiGate, each VPN must be configured to accept connections from a unique peer ID.

Submitted by carter_n· Apr 18, 2026VPN and ZTNA

Question

What is required in a FortiGate configuration to have more than one dialup IPsec VPN using aggressive mode?

Options

  • AAll the aggressive mode dialup VPNs MUST accept connections from the same peer ID.
  • BEach peer ID MUST match the FQDN of each remote peer.
  • CEach aggressive mode dialup MUST accept connections from different peer ID.
  • DThe peer ID setting must NOT be used.

How the community answered

(53 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    92% (49)
  • D
    4% (2)

Why each option

To configure multiple aggressive mode dialup IPsec VPNs on a FortiGate, each VPN must be configured to accept connections from a unique peer ID.

AAll the aggressive mode dialup VPNs MUST accept connections from the same peer ID.

Using the same peer ID for multiple aggressive mode dialup VPNs would prevent the FortiGate from correctly identifying and authenticating different remote clients, leading to connection failures.

BEach peer ID MUST match the FQDN of each remote peer.

While an FQDN can be used as a peer ID, it is not a mandatory requirement for every remote peer; other forms of identification, like an IP address or user FQDN, are also valid.

CEach aggressive mode dialup MUST accept connections from different peer ID.Correct

In aggressive mode, the FortiGate relies on the Peer ID to uniquely identify and authenticate each remote dialup client during Phase 1 negotiation, therefore requiring different peer IDs for each distinct VPN tunnel.

DThe peer ID setting must NOT be used.

The peer ID setting is essential for identifying and authenticating aggressive mode dialup clients; not using it would prevent the establishment of the VPN.

Concept tested: Aggressive mode IPsec dialup peer ID

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/708579/configuring-ipsec-vpn

Topics

#IPsec VPN#Aggressive Mode#Dialup VPN#Peer ID

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice