Be able to configure and troubleshoot IPsec and SSL VPN authentication on FortiGate. The single most important skill is using diagnose vpn ike config, diagnose vpn tunnel list, and IKE debug to determine why a tunnel or user traffic fails.
Start practicing
Authentication and VPN — choose a session length
Free · No account required
Domain overview
This domain covers FortiGate authentication and VPN configuration and troubleshooting, roughly 20% of the NSE4 exam. Expect scenario questions on IPsec Phase 1/Phase 2, dial-up VPNs, SSL VPN, user groups, captive portal, and FortiClient. You must interpret diagnose commands and debug output to isolate failures.
Exam objectives
Interpreting 'diagnose vpn ike config' output, including peer-id: any meaning
Captive portal purpose for authenticating users before granting network access
Troubleshooting dial-up IPsec VPNs where Phase 1 and Phase 2 are up
Reading 'diagnose debug application ike -1' and 'diagnose vpn tunnel list' output
Assuming Phase 1 and Phase 2 'up' means traffic passes; routing, firewall policy, or selectors may still block it.
Misreading 'peer-id: any' as an error; it means the FortiGate accepts any peer identifier during IKE negotiation.
Confusing captive portal authentication with SSL VPN portal; captive portal controls web access, not tunnel establishment.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A remote user reports that they can connect to the FortiGate SSL VPN portal but cannot access internal resources. The administrator checks the SSL VPN settings and sees that the tunnel mode is enabled with split tunneling. What is the most likely cause?
2An administrator is configuring a site-to-site IPsec VPN between two FortiGates. After applying the configuration, the VPN status shows 'down'. Phase 1 parameters are identical on both sides. What is the most likely cause of the failure?
3A company with multiple remote sites uses IPsec VPNs. One site reports intermittent connectivity. The administrator checks the logs and sees 'IPsec phase 2 negotiation failed' messages. Which configuration change is most likely to resolve the issue?
4An administrator is troubleshooting an SSL VPN connection issue. Users can authenticate but receive 'No available tunnel' error. What is the most likely cause?
5A site-to-site IPsec VPN is configured with IKEv2. The tunnel establishes but traffic does not pass. Which two troubleshooting steps should the administrator perform first?
6A FortiGate administrator is designing an SSL VPN solution for 500 remote users. The users need full network access. Which two design considerations are most important?
7An administrator is configuring a dialup IPsec VPN for remote users. Which two settings must be configured on the FortiGate to allow clients to connect?
8A company has a FortiGate at headquarters running FortiOS 7.2 and a remote office with a FortiGate 60F running FortiOS 7.0. They have an IPsec VPN tunnel between them for site-to-site connectivity. Recently, the remote office upgraded their FortiGate from 6.4 to 7.0. After the upgrade, the VPN tunnel is down. The Phase 1 status shows 'negotiating' but never completes. The administrator has verified that the pre-shared key, IKE version (IKEv2), and authentication method are the same on both sides. The Phase 1 proposal on the headquarters is: encryption: AES256, SHA256, DH group 14, lifetime 86400. The remote office uses: encryption: AES256, SHA1, DH group 14, lifetime 86400. What is the most likely cause of the failure?
9A company wants to provide remote access to internal resources for employees using laptops that may connect from untrusted networks. The security team requires that all traffic between the remote users and the corporate network be encrypted, and that users must authenticate using a username/password plus a one-time passcode from a hardware token. Which FortiGate VPN solution best meets these requirements?
10Which TWO are best practices for configuring IPsec VPN on FortiGate to ensure high availability and security?
11Drag and drop the steps to upgrade FortiGate firmware via the web interface into the correct order.
12A network administrator is troubleshooting an IPsec VPN tunnel between two FortiGates. Phase 1 is up, but Phase 2 fails to establish. The debug command 'diagnose vpn ike log' shows: 'no suitable proposal found'. What is the most likely cause?
13An organization wants to use FortiToken for two-factor authentication on SSL VPN logins. Which authentication method must be enabled on the FortiGate to support this?
14A FortiGate is configured with FSSO for firewall authentication. Users report they are prompted for credentials every time they access the internet, even though they are logged into the domain. What is the most likely cause?
15An administrator configures a dial-up IPsec VPN using IKEv2 with certificates. Remote users can connect, but traffic is not routed through the tunnel. The Phase 1 status shows 'up', but Phase 2 shows 'down'. What is the most likely issue?
16A company wants to use captive portal authentication on a guest Wi-Fi network. The FortiGate is connected to the switchport of the access point. Which firewall configuration is required to redirect unauthenticated users to the captive portal?
17What is the primary difference between route-based and policy-based IPsec VPNs on a FortiGate?
18During an IPsec VPN troubleshooting, you run 'diagnose vpn ike config' and see the output includes 'peer-id: any'. What does this mean?
19A FortiGate is configured in an HA active-passive cluster. When the active unit fails, the passive unit takes over, but IPsec VPN tunnels fail to re-establish. The configuration is synchronized. What is the most likely cause?
20What is the purpose of a 'realm' in FortiGate SSL VPN configuration?
21An administrator wants to use ZTNA (Zero Trust Network Access) to secure access to an internal application. Which component is required on the client device to enforce ZTNA policies?
22An organization uses LDAP authentication for firewall policies. Users complain that they are frequently prompted for credentials. Which TWO settings can reduce the frequency of authentication prompts?
23A network administrator configures an IPsec VPN between two FortiGate devices. Phase 1 completes successfully, but Phase 2 fails to establish. The administrator runs 'diagnose vpn ike log' and sees the error 'proposal mismatch'. What is the MOST likely cause?
24A FortiGate administrator is troubleshooting a dial-up IPsec VPN where remote users can connect but traffic does not pass. The Phase 1 and Phase 2 status show 'up'. The administrator runs 'diagnose vpn tunnel list' and sees the tunnel is up. However, 'diagnose sys session list' shows no sessions for the remote user's IP. What is the MOST likely cause?
25A FortiGate administrator wants to authenticate VPN users against an existing LDAP server. The administrator creates an LDAP user group on the FortiGate. What additional configuration is REQUIRED to use this group for IPsec VPN authentication?
26An administrator receives a report that some users cannot authenticate via captive portal on a FortiGate. The captive portal is configured for firewall authentication. The administrator checks the authentication logs and sees 'Authentication failed: invalid credentials'. However, the users confirm they are entering the correct username and password. What is the MOST likely cause?
27A FortiGate administrator is configuring an SSL VPN web mode portal. The administrator wants users to access only a specific internal web application (https://internal-app.company.local) and nothing else. Which SSL VPN setting should be configured to achieve this?
28A FortiGate administrator is configuring a route-based IPsec VPN between two FortiGate devices. After setting up the tunnel and firewall policies, traffic does not flow. The administrator runs 'diagnose vpn tunnel list' and sees the tunnel is up. 'get router info routing-table all' shows routes on both sides. However, pings from the local network to the remote network fail. What is the MOST likely cause?
29Which authentication method allows a FortiGate to transparently authenticate users based on their Active Directory login events without prompting for credentials?
30A FortiGate admin is troubleshooting an IPsec VPN tunnel that fails to establish. The remote site uses aggressive mode. The local FortiGate is configured for main mode. The admin sees 'no proposal chosen' in the IKE debug. What is the MOST likely cause?
31A FortiGate administrator is configuring ZTNA to secure access to an internal application. The administrator creates a ZTNA access proxy and a ZTNA rule. However, users connecting from the internet receive a 403 Forbidden error. The administrator verifies that the users are authenticated and the application is reachable. What is the MOST likely cause?
32An administrator runs 'diagnose debug application fnbamd -1' on a FortiGate to troubleshoot authentication issues. The output shows that the FortiGate successfully contacts the LDAP server but the user authentication fails. What does this indicate?
33A FortiGate admin is configuring a hub-and-spoke IPsec VPN. The hub has multiple phase 2 configurations for each spoke. The spokes can communicate with the hub but not with each other. The admin wants to allow spoke-to-spoke traffic through the hub. Which configuration change is required on the hub?
34A FortiGate administrator is troubleshooting an IPsec VPN between two FortiGates. The tunnel is established, but traffic is not passing. The administrator runs 'diagnose vpn ike log' and sees the following output: IKE: phase 2 negotiation completed IKE: IPsec SA up What THREE possible causes should the administrator investigate?
35A FortiGate administrator is configuring FSSO to authenticate users transparently. The FSSO collector agent is installed on a Windows server in the domain. Which TWO requirements must be met for FSSO to work correctly?
36You are troubleshooting an IPsec VPN between two FortiGates. The Phase 1 is up, but Phase 2 is not coming up. You check the Phase 2 configuration on both sides. What is a common cause of this issue?
37A FortiGate administrator wants to configure a captive portal to authenticate users before granting network access. Which authentication method is used by the captive portal?
38A FortiGate administrator runs 'diagnose vpn tunnel list' and sees the following output for an IPsec tunnel: 'status: up', 'incoming: 0 packets', 'outgoing: 100 packets'. Phase 1 and Phase 2 both show state 'up'. What is the MOST likely cause of zero incoming packets?
39A FortiGate admin has configured FSSO (Fortinet Single Sign-On) using Active Directory polling. Users authenticate to the domain but when accessing the internet through the FortiGate, they are still prompted for credentials. What is the MOST likely cause?
40Which authentication server type can be used with FortiGate to authenticate remote VPN users with two-factor authentication using FortiTokens?
41An admin is configuring a dial-up IPsec VPN for remote users. The users will connect from various public IP addresses. Which Phase 1 configuration is required for the FortiGate to accept connections from unknown remote gateways?
42You run 'diagnose debug application ike -1' and see the following output: 'Initiator: no acceptable proposal'. What is the MOST likely cause of this error?
43In Fortinet ZTNA, what is the primary purpose of the ZTNA access proxy component?
44An admin needs to configure an SSL VPN for remote users that only provides access to specific internal applications, not full network access. What feature should be configured?
45A FortiGate administrator has configured a hub-and-spoke IPsec VPN. The hub FortiGate has two Phase 2 selectors with spokes, but traffic between spokes is not routed via the hub. What must be configured on the hub to allow spoke-to-spoke communication?
46An administrator configures an LDAP user group for firewall authentication. Users are able to authenticate, but the FortiGate does not retrieve group membership information. What is likely misconfigured?
47You are configuring a route-based IPsec VPN with BGP over the tunnel. After Phase 2 is up, the BGP session does not establish. You run 'diagnose debug ipsec' and see no errors. What should you check next?
48An administrator is troubleshooting an SSL VPN connection. Users can connect but cannot access internal resources. Which TWO commands would help diagnose the issue?
49A FortiGate is configured with FSSO and Active Directory polling. Users report that they are frequently prompted for authentication even though they are logged into the domain. Which THREE possible causes should the administrator investigate?
50A network admin configures a site-to-site IPsec VPN between two FortiGates using IKEv1 main mode. The tunnel establishes successfully, but no traffic passes. What is the MOST likely cause?
51An admin needs to authenticate remote users connecting via SSL VPN. The users are in an Active Directory domain. Which authentication method should be configured on the FortiGate to allow users to log in with their domain credentials?
52You run the command 'diagnose vpn ike log filter name vpn1' and then 'diagnose vpn ike log filter type phase1'. The log shows: 'IKEv1 exchange:f4470f07:00000000: responder: main mode: received IKE_SA_INIT (aggressive mode not allowed)'. What is the problem?
53A FortiGate with multiple VDOMs is configured for FSSO with Active Directory polling. Users in VDOM1 are authenticated correctly, but users in VDOM2 are not. What should be checked FIRST?
54Which IPsec VPN mode uses IP addresses and ports to define interesting traffic, and requires a separate security policy for each tunnel?
55You are troubleshooting an SSL VPN connection. The user can reach the SSL VPN portal but cannot ping or access any internal resources. The portal shows the user as authenticated. Which configuration is MOST likely missing?
56What is the primary purpose of the captive portal feature on a FortiGate?
57You have a hub-and-spoke IPsec VPN with 10 spokes. The central FortiGate (hub) has 10 phase2 selectors, one for each spoke. You need to add a new spoke. What is the MOST efficient way to configure the hub?
58After upgrading FortiOS, an IPsec VPN tunnel fails to come up. The diagnose output shows 'negotiation failed: no acceptable proposal'. The remote peer is a third-party device. Which step should you take first?
59An admin wants users to authenticate once via AD and have their network access controlled without repeated logins. Which feature should be used?
60A FortiGate administrator is troubleshooting an SSL VPN issue where remote users cannot access internal resources after successful authentication. Which TWO steps should the admin take to resolve the issue? (Select two.)
61A company sets up a hub-and-spoke IPsec VPN where all spokes must communicate through the hub. The hub uses policy-based IPsec. Which THREE configurations are required on the hub to allow spoke-to-spoke traffic? (Select three.)
62An organization wants to implement ZTNA (Zero Trust Network Access) on their FortiGate. Which TWO components are essential for ZTNA? (Select two.)
63An administrator runs 'diagnose debug application ike -1' and sees the following output: ike 0:come to x.x.x.x:500, IKEv1, cookie 123456789abcdef0 ike 0:incoming IKE packet: src y.y.y.y:500, dst x.x.x.x:500, len 456 ike 0:send IKE packet: src x.x.x.x:500, dst y.y.y.y:500, len 456 ike 0:phase 1 negotiation failed due to time out. What is the likely cause?
64An administrator wants to allow remote users to access internal resources using a web browser without installing any client software. Which VPN type should be configured on the FortiGate?
65A company uses Active Directory for user authentication. They want users to automatically authenticate to the FortiGate without entering credentials when accessing the internet. Which authentication method should the administrator configure?
66An administrator is troubleshooting an IPsec VPN that fails to establish. The 'diagnose vpn ike log' shows 'initial contact received'. What does this message indicate?
67Which of the following FortiGate features allows users to authenticate using a one-time password generated by a mobile app?
68An administrator wants to restrict SSL VPN access to only users who have a valid client certificate issued by the company's internal CA. Which setting should be configured?
69A FortiGate administrator has configured a route-based IPsec VPN. After Phase 2 is up, traffic is not passing. The administrator verifies that the firewall policy allows traffic and the routes are correct. What should the administrator check next?
70An administrator is configuring ZTNA on a FortiGate. The goal is to allow access to an internal web server only if the client device has a specific security posture (e.g., antivirus running). Which ZTNA component is responsible for verifying the client's security posture?
71An administrator has configured LDAP authentication on a FortiGate. When testing the LDAP connectivity, the test succeeds. However, users cannot authenticate through the captive portal. What is a possible cause?
72An administrator is troubleshooting an IPsec VPN that is not passing traffic. The Phase 1 and Phase 2 are both up. Which TWO CLI commands can be used to verify the VPN tunnel status and traffic flow? (Choose two.)
73Which authentication method allows FortiGate to authenticate users against an Active Directory domain without storing domain credentials locally?
74A remote user connects via SSL VPN web mode but cannot access internal resources. The SSL VPN portal is configured with the default settings. What is the most likely reason?
75You run the following command on a FortiGate: diagnose vpn ike gateway list. The output shows a gateway with state=DOWN. What is the most likely cause?
76A FortiGate is configured with IPsec VPN using IKEv2 and a policy-based tunnel. The remote subnet is 10.0.2.0/24, and the local subnet is 192.168.1.0/24. The tunnel is up, but traffic from 192.168.1.0/24 to 10.0.2.0/24 fails. The administrator checks the firewall policy and sees a policy allowing traffic from the local interface (port1) to the remote interface (virtual ipsec interface) with the action set to IPSEC. What is the most likely missing configuration?
77What is the primary function of Fortinet Single Sign-On (FSSO) in a FortiGate deployment?
78An administrator configures a dial-up IPsec VPN with IKEv1 main mode. Remote clients can connect successfully, but the administrator notices that the Phase 1 negotiation takes a long time. Which change would most improve the negotiation speed without compromising security?
79You run 'diagnose debug application sslvpn -1' and see the following output: sslvpn: SSL VPN tunnel mode connection from 10.0.0.5:12345 to 192.168.1.100:443 sslvpn: User 'john' authenticated successfully sslvpn: Error: no matching policy for the request. What does this indicate?
80What is the purpose of a ZTNA (Zero Trust Network Access) tag on a FortiGate?
81A FortiGate is configured as a hub in a hub-and-spoke IPsec VPN. The spokes are remote branches. The hub has a Phase 2 selector set to 0.0.0.0/0 for both local and remote subnets. What is the advantage of this configuration?
82An administrator needs to implement two-factor authentication for SSL VPN access using FortiToken. Which configuration steps are required?
83Which of the following is a characteristic of route-based IPsec VPN compared to policy-based IPsec VPN?
84A network administrator configured an IPsec VPN between two FortiGates. Phase 1 is up, but Phase 2 fails to establish. The diagnose output shows 'no matching proposal'. What is the MOST likely cause?
85A FortiGate admin wants to authenticate VPN users against an existing Microsoft Active Directory. Which authentication method should be configured on the FortiGate?
86Which IPsec VPN mode is typically used for site-to-site VPNs and is more secure because it negotiates Phase 1 in six messages?
87A FortiGate admin configures a captive portal for guest users on a wireless network. Users can connect to the SSID but cannot access the internet. The admin verifies the firewall policy permits traffic from the captive portal interface to the internet. What is missing?
88An administrator runs 'diagnose vpn ike config' and sees the output includes 'P2 proposals: aes128-sha256, aes256-sha1'. What does this indicate?
89A FortiGate in a hub-and-spoke VPN topology has multiple spoke sites connecting via IPsec. The hub administrator wants to enable direct spoke-to-spoke communication without routing traffic through the hub. What technology should be used?
90Which of the following is a benefit of using IKEv2 over IKEv1 for IPsec VPN?
91A FortiGate admin configures a remote user for SSL VPN tunnel mode. The user can connect but cannot access resources on the internal network. The admin checks the SSL VPN settings: tunnel mode enabled, split tunneling disabled. What is the issue?
92An organization is implementing two-factor authentication for SSL VPN access using FortiToken. Which THREE components are necessary for this setup?
93A FortiGate admin wants to implement ZTNA to secure access to an internal application. Which TWO components are required for a basic ZTNA configuration?
94A network administrator wants to authenticate VPN users against an existing LDAP server. Which authentication method should be configured on the FortiGate?
95You run the following CLI command on a FortiGate: 'diagnose vpn ike config list'. The output includes: 'src 10.0.1.0/24:0 dst 192.168.1.0/24:0'. What does this indicate?
96Which of the following best describes the purpose of a captive portal on a FortiGate?
97An administrator is troubleshooting an IPsec VPN that fails to establish Phase 2. The Phase 1 is up. The administrator runs 'diagnose vpn ike log' and sees the message 'no matching phase2 proposal found'. What is the MOST likely cause?
98What is the primary advantage of using IKEv2 over IKEv1 for IPsec VPN?
99When configuring a route-based IPsec VPN, which of the following must be created to allow traffic to flow through the tunnel?
100A FortiGate administrator is configuring a hub-and-spoke IPsec VPN. The hub has multiple Phase 2 selectors for each spoke. What is the recommended way to simplify configuration on the hub when adding new spokes?
101An administrator wants to use Fortinet Single Sign-On (FSSO) with Active Directory to transparently authenticate users. Which component is responsible for polling Active Directory for user logon events?
102A FortiGate administrator is troubleshooting an IPsec VPN that is dropping traffic intermittently. The administrator runs 'diagnose vpn ike log' and sees many 'DPD' messages. Which THREE conditions could cause frequent DPD (Dead Peer Detection) retransmissions? (Choose three.)
103An administrator is configuring a FortiGate for ZTNA (Zero Trust Network Access). Which TWO components are essential for ZTNA to function? (Choose two.)
104What is the primary purpose of configuring split tunneling on an SSL VPN?
105A FortiGate administrator wants to configure a dial-up IPsec VPN where remote users connect using VPN clients with pre-shared key authentication. The company has recently experienced a data breach where the PSK was compromised. What is the best method to improve security without changing all clients immediately?
106A FortiGate administrator configures an SSL VPN web mode portal. Users can access internal web applications but cannot access internal file shares via SMB. What is the most likely reason?
107You receive an alert that a user's FortiToken synchronization is off. You need to resynchronize the token. Which CLI command achieves this?
108In a hub-and-spoke IPsec VPN topology with FortiGate, the spoke sites cannot communicate directly with each other. What configuration change allows direct spoke-to-spoke communication?
109What is the primary advantage of using route-based IPsec VPN over policy-based IPsec VPN?
110A FortiGate administrator is troubleshooting an SSL VPN connection issue. Users can connect but cannot access internal resources. The administrator checks the SSL VPN policy and confirms it allows access to the internal subnet. What should the administrator check next?
111A FortiGate administrator is configuring ZTNA for a web application. Which TWO components are required for a ZTNA configuration to function?
112A FortiGate administrator is configuring RADIUS authentication for firewall users. Which THREE steps are required to complete the configuration? (Select THREE.)
113A FortiGate is configured with an IPsec VPN to a remote site using IKEv1. The VPN tunnel goes down intermittently. The admin runs 'diagnose vpn ike gateway list' and sees 'state=UP' but no Phase2 selectors. What is the most likely cause?
114An administrator wants to use Active Directory credentials to authenticate firewall administrators. Which authentication server type should be configured on the FortiGate?
115A FortiGate in a hub-and-spoke VPN topology is configured with a single IPsec tunnel to each spoke. The hub has a route-based VPN with a tunnel interface for each spoke. After a reboot, traffic between spoke A and spoke B fails, although each spoke can reach the hub. What is the likely cause?
116A client connects to a FortiGate SSL VPN in web mode. The user can access internal web applications but cannot ping or RDP to servers. The administrator wants to allow these services. What must be changed?
117The output of 'diagnose debug application ike -1' shows 'no proposal chosen' for a Phase1 negotiation. Which action should the administrator take to resolve this?
118A FortiGate administrator needs to authenticate VPN users against an LDAP server. What is the primary purpose of the 'CN=,OU=,DC=' distinguished name (DN) configured in the LDAP server settings?
119During an SSL VPN tunnel mode connection, the client reports that they cannot access any internal resources, but the VPN connection is established. The FortiGate debug shows 'no matching policy'. The administrator has configured a policy allowing the SSL VPN interface to internal. What else must be configured?
120An administrator is troubleshooting an IPsec VPN that uses aggressive mode. The VPN establishes successfully, but the administrator is concerned about security. Which statement is true regarding aggressive mode?
121A company uses Fortinet Single Sign-On (FSSO) to authenticate users for firewall policies. The FSSO collector agent is installed on a Windows server and configured with Active Directory polling. What does the collector agent do?
122An administrator runs 'diagnose vpn ssl stat' and sees 'tun-num: 5, clients: 0'. Users are unable to connect to the SSL VPN. The SSL VPN settings are correct and the certificate is valid. What could be the cause?
123An administrator configures a captive portal on the FortiGate to authenticate guest users via a local user database. Users can connect to the SSID, but after entering credentials on the captive portal, they are not redirected to the internet. What is the most likely missing configuration?
124An administrator is configuring an IPsec VPN between two FortiGates using IKEv1. The tunnel must use main mode and support multiple subnets behind each gate. Which Phase2 settings are required to allow multiple subnets? (Choose two.)
125An administrator needs to configure ZTNA (Zero Trust Network Access) on a FortiGate to provide secure remote access to an internal application. Which components are required for a basic ZTNA configuration? (Choose three.)
126A FortiGate administrator wants to authenticate VPN users against an existing Active Directory server. The administrator creates a user group referencing a remote LDAP server and configures the firewall policy to authenticate using that group. However, users report authentication failures. What is the FIRST step to troubleshoot?
127An administrator configures a dial-up IPsec VPN with IKEv2 to allow remote users to connect. The Phase 1 is set to use certificate-based authentication (PKI). Users can establish Phase 1, but Phase 2 fails with 'no proposal chosen'. The administrator checks the Phase 2 proposal: AES256-SHA256, and the remote network is 10.0.0.0/8 (the corporate LAN). What is the MOST likely cause?
128A FortiGate is configured with FSSO (Fortinet Single Sign-On) to authenticate users from Active Directory. Users are logging in to their domain-joined computers, but the FortiGate does not see the user sessions. The polling connector is configured correctly. What is the MOST likely reason?
129An administrator wants to configure SSL VPN web mode to allow remote users to access a specific internal web application without installing any client software. Which authentication method is required?
130An administrator runs 'diagnose vpn ike gateway list' on a FortiGate and sees the following output for a dial-up IPsec VPN: gateway name: 'dialup' version: IKEv1 mode: aggressive local IP: 203.0.113.1 remote IP: 0.0.0.0 state: up peers: 0 What does 'peers: 0' indicate?
131A FortiGate administrator configures a captive portal on a VDOM to authenticate users connecting to a guest SSID. The authentication method is set to LDAP. Users can reach the captive portal login page, but after entering valid credentials, they receive an authentication failure. The LDAP server is reachable from the FortiGate. What is the MOST likely cause?
132An administrator configures a route-based IPsec VPN between two FortiGates. The Phase 1 and Phase 2 are up. The administrator adds a static route on each FortiGate pointing to the remote subnet via the virtual tunnel interface (e.g., 'to_remote'). Traffic between the subnets fails. What is the MOST likely missing configuration?
133An administrator needs to configure two-factor authentication for SSL VPN users using FortiToken. Which configuration is required on the FortiGate?
134A FortiGate administrator is troubleshooting an IPsec VPN that fails to establish. The Phase 1 status shows 'init' and then resets. The administrator runs 'diagnose debug application ike -1' and sees the message 'no acceptable proposal'. Which TWO parameters are MOST likely mismatched?
135An administrator wants to implement ZTNA (Zero Trust Network Access) on a FortiGate to secure access to an internal application. Which TWO components are essential for a ZTNA configuration?
136An administrator needs to authenticate users on a FortiGate using RADIUS. Which TWO of the following are required to configure RADIUS authentication?
137A FortiGate administrator is configuring a hub-and-spoke IPsec VPN with three spokes. Each spoke has a dial-up connection to the hub. The hub uses a dynamic DNS name. Which THREE settings are necessary on each spoke to establish the VPN?
138A network admin configures an IPsec VPN between two FortiGates using IKEv2. Phase 1 completes successfully, but Phase 2 fails to establish. The admin runs 'diagnose vpn ike log' and sees the error 'proposal mismatch'. What is the most likely cause?
139An administrator wants to authenticate VPN users against an external LDAP server. Which authentication method should be configured in the user group for the SSL VPN portal?
140A FortiGate is configured with FSSO using a DC agent. Users authenticate to the domain, but the firewall policy using FSSO groups is not matching traffic. The admin runs 'diagnose debug authd fsso list' and sees user entries. However, the traffic is being denied by the default deny policy. What is the most likely issue?
141Which mode of SSL VPN provides full network-layer access to the remote network, allowing any application to function as if the client is directly connected?
142An administrator is troubleshooting an IPsec VPN between two FortiGates. Phase 1 is up but Phase 2 is down. The admin runs 'diagnose vpn ike log' and sees 'no matching proposal'. To resolve this issue, which TWO settings should be checked on both ends?
143A FortiGate is configured as an SSL VPN server with tunnel mode. Remote users authenticate successfully, but after connecting they cannot reach any internal subnet. The administrator verifies that the SSL VPN firewall policy allows the tunnel interface and that the internal routes exist. Which SSL VPN configuration setting must be checked next to ensure that the correct routes are pushed to the clients?
144A FortiGate administrator is configuring a new SSL VPN portal for employees. The requirement is that employees must authenticate using their Active Directory credentials, and after authentication, they should only be able to access a specific internal web server via a bookmarked link. Which SSL VPN configuration should the administrator use to meet these requirements?
145A network administrator is configuring a site-to-site IPsec VPN between two FortiGates. Phase 1 and Phase 2 are both up, but traffic is not passing through the tunnel. The administrator runs 'diagnose debug flow' and sees that packets are being dropped with the message 'iprope_in_check() check failed, drop'. Which configuration change is most likely to resolve this issue?
146An administrator is configuring a FortiGate to use LDAP for firewall authentication. Users are prompted for their credentials when accessing the internet. After successful authentication, users can access the internet. However, the administrator notices that users are prompted again after 30 minutes of inactivity. Which setting should the administrator adjust to extend the authentication timeout?
147A FortiGate administrator is configuring a dial-up IPsec VPN for remote users. The users will connect from various locations with dynamic public IP addresses. The administrator wants to ensure that the VPN is secure and that only authorized users can connect. Which two Phase 1 configuration settings are required to support this scenario? (Choose two.)
148A FortiGate administrator is configuring FSSO with Active Directory polling. Users in the 'Sales' group are not being authenticated correctly, while users in the 'IT' group are working fine. The administrator verifies that the FSSO agent is connected and polling the domain controllers. Which action should the administrator take to troubleshoot the issue?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to configure and troubleshoot IPsec and SSL VPN authentication on FortiGate. The single most important skill is using diagnose vpn ike config, diagnose vpn tunnel list, and IKE debug to determine why a tunnel or user traffic fails.
The Courseiva NSE4 question bank contains 148 questions in the Authentication and VPN domain, covering the 20% of the exam attributed to this domain in the official Fortinet blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Authentication and VPN domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included