FORTINET-NSE123 Practice Question: Nse 2 Technical Introduction TO Fortinet Security
An enterprise network architect is designing a site-to-site VPN architecture to connect a branch office to headquarters using FortiGate devices. The branch office relies on a dynamic broadband connection with a frequently changing public IP address. Which VPN configuration approach should be implemented?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a site-to-site IPsec VPN with the headquarters acting as the dial-up server and the branch acting as the dial-up client.
When one peer has a dynamic IP address, Main Mode IPsec VPNs with dynamic dial-up user settings or Aggressive Mode with dynamic ID peer IDs are typically used. In modern FortiOS, dial-up IPsec VPN configurations allow the dynamically addressed branch to initiate the tunnel to the static headquarters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement Virtual Domain (VDOM) links to bridge the branch office directly to headquarters across Layer 2.
Why it's wrong here
VDOM links operate locally within a single FortiGate device and do not span across public WAN connections.
- ✗
Configure static IPsec phase 1 parameters specifying the exact public IP address of the branch office on the headquarters FortiGate.
Why it's wrong here
Static IP addressing on both ends will fail if the branch office public IP address changes frequently.
- ✗
Configure an SSL VPN web portal on the branch office FortiGate.
Why it's wrong here
SSL VPN portals are typically used for remote user access rather than permanent site-to-site backbone connectivity.
- ✓
Configure a site-to-site IPsec VPN with the headquarters acting as the dial-up server and the branch acting as the dial-up client.
Why this is correct
A dial-up IPsec VPN setup accommodates branch offices with dynamic public IPs by having the static headquarters listen for incoming connections from dynamic peers.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every FORTINET-NSE123 question from scratch — 296 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Fortinet exam blueprint
This FORTINET-NSE123 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FORTINET-NSE123 exam.