nerdexam
Fortinet

NSE4 · Question #97

An administrator wants to create an IPsec VPN tunnel between two FortiGate devices. Which three configuration steps must be performed on both units to support this scenario? (Choose three.)

The correct answer is A. Create firewall policies to allow and control traffic between the source and destination IP D. Define the phase 2 parameters. E. Define the Phase 1 parameters. This question asks for three essential configuration steps required on both FortiGate devices to establish an IPsec VPN tunnel between them.

Submitted by skyler.x· Apr 18, 2026VPN and Routing

Question

An administrator wants to create an IPsec VPN tunnel between two FortiGate devices. Which three configuration steps must be performed on both units to support this scenario? (Choose three.)

Options

  • ACreate firewall policies to allow and control traffic between the source and destination IP
  • BConfigure the appropriate user groups to allow users access to the tunnel.
  • CSet the operating mode to IPsec VPN mode.
  • DDefine the phase 2 parameters.
  • EDefine the Phase 1 parameters.

How the community answered

(18 responses)
  • A
    83% (15)
  • B
    11% (2)
  • C
    6% (1)

Why each option

This question asks for three essential configuration steps required on both FortiGate devices to establish an IPsec VPN tunnel between them.

ACreate firewall policies to allow and control traffic between the source and destination IPCorrect

Firewall policies are crucial for controlling which traffic is allowed to traverse the VPN tunnel once it is established, defining the source, destination, service, and action for traffic passing between the internal networks and the VPN interface.

BConfigure the appropriate user groups to allow users access to the tunnel.

Configuring user groups is relevant for client-to-site VPNs or user-based access control, but it's not a mandatory step for establishing a basic site-to-site IPsec tunnel between two FortiGate devices.

CSet the operating mode to IPsec VPN mode.

FortiGates operate in various modes, but there isn't a specific 'IPsec VPN mode' for the entire device; IPsec VPNs are a feature configured within the device's existing operating mode.

DDefine the phase 2 parameters.Correct

Phase 2 parameters define the security associations for the actual data tunnel, including encryption and authentication algorithms for data transfer, PFS settings, and key lifetimes, which must match on both VPN peers for the tunnel to establish.

EDefine the Phase 1 parameters.Correct

Phase 1 parameters, or the Internet Key Exchange (IKE) phase, define how VPN peers authenticate and establish a secure channel for exchanging Phase 2 keys, and these settings must be identical on both FortiGates.

Concept tested: FortiGate site-to-site IPsec VPN basic configuration

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/52643/example-configuring-a-route-based-vpn

Topics

#IPsec VPN#Phase 1#Phase 2#Firewall Policy

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice