nerdexam
Fortinet

NSE4 · Question #44

Review the IPsec phase 1 configuration in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)

The correct answer is A. The remote gateway address on 10.200.3.1. C. The local gateway IP is the address assigned to port1. The IPsec phase 1 configuration specifies the remote peer's public IP address as 10.200.3.1 and defines the local gateway IP as the address assigned to the FortiGate's port1 interface.

Submitted by femi9· Apr 18, 2026VPN and Routing

Question

Review the IPsec phase 1 configuration in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)

Exhibit

NSE4 question #44 exhibit

Options

  • AThe remote gateway address on 10.200.3.1.
  • BThe local IPsec interface address is 10.200.3.1.
  • CThe local gateway IP is the address assigned to port1.
  • DThe local gateway IP address is 10.200.3.1.

How the community answered

(35 responses)
  • A
    94% (33)
  • B
    3% (1)
  • D
    3% (1)

Why each option

The IPsec phase 1 configuration specifies the remote peer's public IP address as 10.200.3.1 and defines the local gateway IP as the address assigned to the FortiGate's port1 interface.

AThe remote gateway address on 10.200.3.1.Correct

The remote gateway address explicitly defines the public IP address of the peer VPN device (e.g., another FortiGate) to which the IPsec tunnel will establish its Phase 1 connection, in this case, 10.200.3.1.

BThe local IPsec interface address is 10.200.3.1.

The 'local IPsec interface address' refers to the IP on the FortiGate's interface used for the tunnel, but assuming 10.200.3.1 is the remote gateway (A is correct), it cannot simultaneously be the local interface address in a standard setup.

CThe local gateway IP is the address assigned to port1.Correct

The local gateway IP is the source IP address that the FortiGate uses for IKE negotiations and for establishing the VPN tunnel, which is typically the IP address assigned to the specified outbound network interface (e.g., port1).

DThe local gateway IP address is 10.200.3.1.

If the remote gateway IP address is 10.200.3.1 (as per choice A), then the local gateway IP address cannot also be 10.200.3.1 in a typical site-to-site IPsec VPN configuration without complex and unusual NAT scenarios.

Concept tested: IPsec Phase 1 gateway identification

Source: https://docs.fortinet.com/document/fortigate/7.4.0/cli-reference/169096/config-vpn-ipsec-phase1-interface

Topics

#IPsec VPN#Phase 1#Gateway Configuration#FortiGate

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice