Courseiva
Nse 2 Technical Introduction TO Fortinet SecuritymediumMultiple ChoiceObjective-mapped

FORTINET-NSE123 Practice Question: Nse 2 Technical Introduction TO Fortinet Security

An enterprise network architect is designing a site-to-site VPN architecture to connect a branch office to headquarters using FortiGate devices. The branch office relies on a dynamic broadband connection with a frequently changing public IP address. Which VPN configuration approach should be implemented?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a site-to-site IPsec VPN with the headquarters acting as the dial-up server and the branch acting as the dial-up client.

When one peer has a dynamic IP address, Main Mode IPsec VPNs with dynamic dial-up user settings or Aggressive Mode with dynamic ID peer IDs are typically used. In modern FortiOS, dial-up IPsec VPN configurations allow the dynamically addressed branch to initiate the tunnel to the static headquarters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement Virtual Domain (VDOM) links to bridge the branch office directly to headquarters across Layer 2.

    Why it's wrong here

    VDOM links operate locally within a single FortiGate device and do not span across public WAN connections.

  • Configure static IPsec phase 1 parameters specifying the exact public IP address of the branch office on the headquarters FortiGate.

    Why it's wrong here

    Static IP addressing on both ends will fail if the branch office public IP address changes frequently.

  • Configure an SSL VPN web portal on the branch office FortiGate.

    Why it's wrong here

    SSL VPN portals are typically used for remote user access rather than permanent site-to-site backbone connectivity.

  • Configure a site-to-site IPsec VPN with the headquarters acting as the dial-up server and the branch acting as the dial-up client.

    Why this is correct

    A dial-up IPsec VPN setup accommodates branch offices with dynamic public IPs by having the static headquarters listen for incoming connections from dynamic peers.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every FORTINET-NSE123 question from scratch — 296 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Fortinet exam blueprint

This FORTINET-NSE123 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FORTINET-NSE123 exam.