nerdexam
Fortinet

NSE4 · Question #494

Review the IPsec phase 1 configuration in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)

The correct answer is A. The remote gateway address is 10.200.3.1 C. The local gateway IP is the address assigned to port1. In an IPsec Phase 1 configuration, the remote gateway specifies the peer's public IP address, and the local gateway is determined by the IP address of the FortiGate's designated local interface.

Submitted by brentm· Apr 18, 2026VPN and Routing

Question

Review the IPsec phase 1 configuration in the exhibit; then answer the question below. Which statements are correct regarding this configuration? (Choose two.)

Exhibit

NSE4 question #494 exhibit

Options

  • AThe remote gateway address is 10.200.3.1
  • BThe local IPsec interface address is 10.200.3.1
  • CThe local gateway IP is the address assigned to port1
  • DThe local gateway IP is 10.200.3.1

How the community answered

(33 responses)
  • A
    76% (25)
  • B
    18% (6)
  • D
    6% (2)

Why each option

In an IPsec Phase 1 configuration, the remote gateway specifies the peer's public IP address, and the local gateway is determined by the IP address of the FortiGate's designated local interface.

AThe remote gateway address is 10.200.3.1Correct

In the IPsec Phase 1 configuration, the `Remote Gateway` field is used to specify the public IP address of the peer device with which the FortiGate will establish the VPN tunnel, indicating that 10.200.3.1 is the remote endpoint.

BThe local IPsec interface address is 10.200.3.1

If 10.200.3.1 is specified as the remote gateway, it cannot simultaneously be the local IPsec interface address.

CThe local gateway IP is the address assigned to port1Correct

The `Local Interface` selected in the Phase 1 configuration dictates which FortiGate interface will handle the VPN connection, and its assigned IP address will serve as the local gateway IP for the IPsec tunnel.

DThe local gateway IP is 10.200.3.1

This statement contradicts choice A and implies 10.200.3.1 is the FortiGate's local VPN endpoint, which is incorrect if it's configured as the remote gateway.

Concept tested: FortiGate IPsec Phase 1 configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/142994/phase-1-settings

Topics

#IPsec VPN#Phase 1 Configuration#FortiGate CLI#Gateway Address

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice