nerdexam
Fortinet

NSE4 · Question #546

Which of the following statements about policy-based IPsec tunnels are true? (Choose two.)

The correct answer is B. They can be configured in both NAT/Route and transparent operation modes. C. They require two firewall policies: one for each direction of traffic flow. Policy-based IPsec VPN tunnels can be deployed in both NAT/Route and transparent modes, and they fundamentally require two firewall policies for managing bidirectional traffic flow.

Submitted by priya_blr· Apr 18, 2026VPN and Routing

Question

Which of the following statements about policy-based IPsec tunnels are true? (Choose two.)

Options

  • AThey support GRE-over-IPsec.
  • BThey can be configured in both NAT/Route and transparent operation modes.
  • CThey require two firewall policies: one for each direction of traffic flow.
  • DThey support L2TP-over-IPsec.

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    94% (48)
  • D
    2% (1)

Why each option

Policy-based IPsec VPN tunnels can be deployed in both NAT/Route and transparent modes, and they fundamentally require two firewall policies for managing bidirectional traffic flow.

AThey support GRE-over-IPsec.

GRE-over-IPsec is generally implemented with route-based IPsec VPNs, where GRE tunnels are built over the virtual IPsec interface, not typically with policy-based IPsec which uses traffic selectors.

BThey can be configured in both NAT/Route and transparent operation modes.Correct

Policy-based IPsec tunnels can be configured in both NAT/Route (gateway) mode and transparent (bridge) mode on a FortiGate, providing flexibility for different network architectures.

CThey require two firewall policies: one for each direction of traffic flow.Correct

For policy-based IPsec VPNs, two firewall policies are essential: one policy to permit outbound traffic from the local network into the tunnel, and another policy to permit inbound return traffic from the tunnel to the local network.

DThey support L2TP-over-IPsec.

L2TP-over-IPsec is a distinct VPN technology often used for remote access and is not a direct characteristic or general capability of policy-based IPsec tunnels for site-to-site connectivity.

Concept tested: FortiGate policy-based IPsec VPN characteristics

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/463691/policy-based-ipsec-vpn

Topics

#IPsec VPN#Policy-based VPN#Firewall policies#FortiGate operation modes

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice