nerdexam
Fortinet

NSE4 · Question #448

Which of the following combinations of two FortiGate device configurations (side A and side B), can be used to successfully establish an IPsec VPN between them? (choose two)

The correct answer is B. Side A:main mode, remote gateway as static IP address, policy based VPN. Side B: C. Side A:main mode, remote gateway as static IP address, policy based VPN. Side B:. Successful IPsec VPN establishment requires compatible configurations on both FortiGate devices regarding VPN mode, remote gateway type, and VPN type (policy-based or route-based).

Submitted by ricky.ec· Apr 18, 2026VPN and Routing

Question

Which of the following combinations of two FortiGate device configurations (side A and side B), can be used to successfully establish an IPsec VPN between them? (choose two)

Options

  • ASide A:main mode, remote gateway as static IP address, policy based VPN. Side B:
  • BSide A:main mode, remote gateway as static IP address, policy based VPN. Side B:
  • CSide A:main mode, remote gateway as static IP address, policy based VPN. Side B:
  • DSide A: main mode, remote gateway as dialup policy based VPN, Side B: main mode, remote

How the community answered

(39 responses)
  • A
    8% (3)
  • B
    79% (31)
  • D
    13% (5)

Why each option

Successful IPsec VPN establishment requires compatible configurations on both FortiGate devices regarding VPN mode, remote gateway type, and VPN type (policy-based or route-based).

ASide A:main mode, remote gateway as static IP address, policy based VPN. Side B:

The Side B configuration provided is incomplete, making it impossible to determine if the combination would be successful for IPsec VPN establishment.

BSide A:main mode, remote gateway as static IP address, policy based VPN. Side B:Correct

This combination allows a static IP gateway on Side A to establish a policy-based VPN with a dialup user on Side B, as both sides are configured for main mode and policy-based VPN, ensuring compatible settings.

CSide A:main mode, remote gateway as static IP address, policy based VPN. Side B:Correct

This combination also allows a static IP gateway on Side A to establish a route-based VPN with a dialup user on Side B, as both sides are configured for main mode and route-based VPN, ensuring compatible settings for tunnel establishment.

DSide A: main mode, remote gateway as dialup policy based VPN, Side B: main mode, remote

Side A's configuration as a 'dialup policy based VPN' when also defining a 'remote gateway as dialup policy based VPN' is contradictory, as dialup VPNs typically await connections, and the description is malformed for a peer definition.

Concept tested: IPsec VPN configuration compatibility (FortiGate)

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/453198/ipsec-vpn

Topics

#IPsec VPN#VPN Configuration#Policy-based VPN#FortiGate

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice