nerdexam
Fortinet

NSE4 · Question #500

Which statement is correct concerning an IPsec VPN with the remote gateway setting configured as 'Dynamic DNS'?

The correct answer is D. The remote gateway IP address can change dynamically. Configuring an IPsec VPN remote gateway as 'Dynamic DNS' enables the FortiGate to connect to a peer whose public IP address is not static but dynamically resolved via an FQDN.

Submitted by haru.x· Apr 18, 2026VPN and Routing

Question

Which statement is correct concerning an IPsec VPN with the remote gateway setting configured as 'Dynamic DNS'?

Options

  • AThe FortiGate will accept IPsec VPN connection from any IP address.
  • BThe FQDN resolution of the local FortiGate IP address where the VPN is terminated must be
  • CThe FortiGate will Accept IPsec VPN connections only from IP addresses included on a
  • DThe remote gateway IP address can change dynamically.

How the community answered

(56 responses)
  • A
    9% (5)
  • B
    2% (1)
  • C
    4% (2)
  • D
    86% (48)

Why each option

Configuring an IPsec VPN remote gateway as 'Dynamic DNS' enables the FortiGate to connect to a peer whose public IP address is not static but dynamically resolved via an FQDN.

AThe FortiGate will accept IPsec VPN connection from any IP address.

The FortiGate will not accept connections from "any IP address"; it will only accept connections from the IP address currently resolved by the configured Dynamic DNS hostname.

BThe FQDN resolution of the local FortiGate IP address where the VPN is terminated must be

The FQDN resolution applies to the *remote* gateway's IP address, not necessarily the *local* FortiGate's IP address for the VPN termination.

CThe FortiGate will Accept IPsec VPN connections only from IP addresses included on a

This statement is incorrect as the purpose of Dynamic DNS is to allow for changing IP addresses, not to restrict to a pre-defined static list of IP addresses.

DThe remote gateway IP address can change dynamically.Correct

When a remote gateway is configured with 'Dynamic DNS', the FortiGate expects the remote peer's public IP address to be associated with a Dynamic DNS hostname, allowing the VPN tunnel to be established even if the remote peer's IP address changes dynamically.

Concept tested: IPsec VPN dynamic remote gateway

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/339230/phase-1-settings

Topics

#IPsec VPN#Dynamic DNS#Remote Gateway#VPN Configuration

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice