nerdexam
Fortinet

NSE4 · Question #99

An administrator has configured a route-based site-to-site IPsec VPN. Which statement is correct regarding this IPsec VPN configuration?

The correct answer is D. A virtual IPsec interface is automatically created after the Phase 1 configuration is completed. The question asks for a correct statement about a route-based site-to-site IPsec VPN configuration.

Submitted by satoshi_tk· Apr 18, 2026VPN and Routing

Question

An administrator has configured a route-based site-to-site IPsec VPN. Which statement is correct regarding this IPsec VPN configuration?

Options

  • AThe IPsec firewall policies must be placed at the top of the list.
  • BThis VPN cannot be used as part of a hub and spoke topology.
  • CRoutes are automatically created based on the quick mode selectors.
  • DA virtual IPsec interface is automatically created after the Phase 1 configuration is completed.

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    3% (1)
  • D
    92% (34)

Why each option

The question asks for a correct statement about a route-based site-to-site IPsec VPN configuration.

AThe IPsec firewall policies must be placed at the top of the list.

Firewall policies for IPsec VPNs, like other policies, are evaluated in order, but there's no requirement for them to be at the top of the list; their placement depends on the overall policy hierarchy.

BThis VPN cannot be used as part of a hub and spoke topology.

Route-based VPNs are highly suitable for hub-and-spoke topologies because they allow for routing protocols to exchange routes over the VPN tunnels, simplifying network management.

CRoutes are automatically created based on the quick mode selectors.

In route-based IPsec VPNs, routes to remote subnets are not automatically created based on quick mode (Phase 2) selectors; instead, static routes or dynamic routing protocols must be manually configured to direct traffic through the virtual IPsec interface.

DA virtual IPsec interface is automatically created after the Phase 1 configuration is completed.Correct

In a route-based IPsec VPN configuration on FortiGate, completing the Phase 1 configuration automatically creates a virtual IPsec tunnel interface, which serves as the logical endpoint for the VPN and is used for routing and firewall policies.

Concept tested: FortiGate route-based IPsec VPN characteristics

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/468846/route-based-vs-policy-based-ipsec-vpn

Topics

#IPsec VPN#Route-based VPN#Virtual Interface#FortiGate VPN

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice