nerdexam
Fortinet

NSE4 · Question #549

Why must you use aggressive mode when a local FortiGate IPsec gateway hosts multiple dialup tunnels?

The correct answer is B. FortiClient supports aggressive mode. Aggressive mode is often required for a FortiGate hosting multiple IPsec dialup tunnels because FortiClient, a common remote peer, supports aggressive mode.

Submitted by javi_es· Apr 18, 2026VPN and Routing

Question

Why must you use aggressive mode when a local FortiGate IPsec gateway hosts multiple dialup tunnels?

Options

  • AThe FortiGate is able to handle NATed connections only with aggressive mode.
  • BFortiClient supports aggressive mode.
  • CThe remote peers are able to provide their peer IDs in the first message with aggressive mode.
  • DMain mode does not support XAuth for user authentication.

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    91% (39)
  • C
    2% (1)
  • D
    2% (1)

Why each option

Aggressive mode is often required for a FortiGate hosting multiple IPsec dialup tunnels because FortiClient, a common remote peer, supports aggressive mode.

AThe FortiGate is able to handle NATed connections only with aggressive mode.

FortiGate can handle NATed connections in both main mode and aggressive mode with appropriate NAT traversal (NAT-T) settings.

BFortiClient supports aggressive mode.Correct

FortiClient, a common VPN client used for dial-up IPsec VPNs, primarily supports IKEv1 aggressive mode for establishing connections. If the FortiGate gateway needs to support FortiClient connections from multiple remote users, configuring aggressive mode is necessary for compatibility.

CThe remote peers are able to provide their peer IDs in the first message with aggressive mode.

While aggressive mode allows the peer ID to be sent in the first message, the primary reason for mandating aggressive mode in this scenario for a FortiGate gateway supporting multiple dialup tunnels is FortiClient compatibility, not solely the ID exchange mechanism.

DMain mode does not support XAuth for user authentication.

Main mode can support XAuth for user authentication, especially when combined with Extended Authentication (XAuth) in Phase 1 negotiations.

Concept tested: IPsec Aggressive Mode for FortiGate Dial-up VPNs

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-cookbook/249118/aggressive-mode-with-pre-shared-key-pki-and-xauth

Topics

#IPsec VPN#Aggressive Mode#FortiClient#Remote Access VPN

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice