nerdexam
Fortinet

NSE4 · Question #95

Which IPsec configuration mode can be used for implementing GRE-over-IPsec VPNs?.

The correct answer is B. Route-based only. This question asks which IPsec configuration mode is suitable for implementing GRE-over-IPsec VPNs.

Submitted by certguy· Apr 18, 2026VPN and Routing

Question

Which IPsec configuration mode can be used for implementing GRE-over-IPsec VPNs?.

Options

  • APolicy-based only.
  • BRoute-based only.
  • CEither policy-based or route-based VPN.
  • DGRE-based only.

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    88% (15)
  • C
    6% (1)

Why each option

This question asks which IPsec configuration mode is suitable for implementing GRE-over-IPsec VPNs.

APolicy-based only.

Policy-based IPsec operates by matching traffic against policies and does not create a virtual interface, making it unsuitable for encapsulating GRE tunnels.

BRoute-based only.Correct

GRE-over-IPsec VPNs require the creation of a virtual tunnel interface (VTI) for GRE, and then IPsec is applied to protect this GRE tunnel, which necessitates route-based IPsec for its interface-based routing capabilities.

CEither policy-based or route-based VPN.

Policy-based VPNs cannot encapsulate GRE, so stating that 'either' mode works is incorrect.

DGRE-based only.

'GRE-based only' is not a recognized IPsec configuration mode; GRE is a separate tunneling protocol that can be protected by IPsec.

Concept tested: IPsec VPN modes for GRE tunnels

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/468846/route-based-vs-policy-based-ipsec-vpn

Topics

#IPsec VPN#Route-based VPN#GRE-over-IPsec#VPN configuration

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice