Courseiva
Authentication and VPN →mediumMultiple Select

NSE4 Authentication and VPN Practice Question

A FortiGate administrator is configuring a dial-up IPsec VPN for remote users. The users will connect from various locations with dynamic public IP addresses. The administrator wants to ensure that the VPN is secure and that only authorized users can connect. Which two Phase 1 configuration settings are required to support this scenario? (Choose two.)

⚠ Common exam trap

The trap here is assuming that Aggressive mode or NAT Traversal are mandatory for dial-up VPNs, when the essential requirements are Dialup User and XAUTH for dynamic IPs and user authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the 'Remote Gateway' to 'Dialup User'.

For a dial-up IPsec VPN with dynamic user IPs, the remote gateway must be set to 'Dialup User' to accept connections from any IP. To authenticate individual users, XAUTH must be enabled, which prompts for username and password after the tunnel is established. These two settings ensure that the VPN can handle dynamic IPs and enforce user authentication. Other settings like Aggressive mode or NAT Traversal may be used but are not required for all scenarios.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the 'Remote Gateway' to 'Dialup User'.

    Why this is correct

    Setting the remote gateway to 'Dialup User' allows the FortiGate to accept connections from any IP address, which is necessary for users with dynamic public IPs. This mode is designed for dial-up VPNs where the remote peer's IP is not known in advance. Without this, the FortiGate would only accept connections from a specific IP.

  • ✗

    Set the 'Remote Gateway' to the specific IP address of each user.

    Why it's wrong here

    Setting a specific remote gateway IP is not feasible for users with dynamic public IP addresses. It would require a separate Phase 1 configuration for each user, which is impractical. The correct approach is to use 'Dialup User' to accept connections from any IP, combined with user authentication.

  • ✓

    Enable 'XAUTH' for extended authentication.

    Why this is correct

    XAUTH (Extended Authentication) is used in dial-up VPNs to authenticate individual users after the IPsec tunnel is established. It requires users to provide credentials, typically via a pre-shared key or certificate for the tunnel, and then username/password for XAUTH. This ensures that only authorized users can connect, which is essential for a dial-up scenario.

  • ✗

    Configure 'Aggressive' mode for Phase 1.

    Why it's wrong here

    Aggressive mode is faster but less secure than Main mode because it exposes the identity of the remote gateway. While it is sometimes used in dial-up VPNs, it is not a requirement and is generally discouraged due to security risks. Main mode is preferred unless there is a specific need for Aggressive mode, such as when the remote gateway has a dynamic IP and the local gateway is static.

  • ✗

    Enable 'NAT Traversal' in Phase 1 settings.

    Why it's wrong here

    NAT Traversal is used when there is a NAT device between the VPN peers. While it is often enabled in dial-up VPNs to handle NAT, it is not strictly required for all scenarios. The question asks for required settings to support dynamic IPs and secure authentication; NAT Traversal is beneficial but not mandatory. The essential settings are Dialup User and XAUTH.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.