NSE4 Authentication and VPN Practice Question
A FortiGate administrator is configuring a dial-up IPsec VPN for remote users. The users will connect from various locations with dynamic public IP addresses. The administrator wants to ensure that the VPN is secure and that only authorized users can connect. Which two Phase 1 configuration settings are required to support this scenario? (Choose two.)
⚠ Common exam trap
The trap here is assuming that Aggressive mode or NAT Traversal are mandatory for dial-up VPNs, when the essential requirements are Dialup User and XAUTH for dynamic IPs and user authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the 'Remote Gateway' to 'Dialup User'.
For a dial-up IPsec VPN with dynamic user IPs, the remote gateway must be set to 'Dialup User' to accept connections from any IP. To authenticate individual users, XAUTH must be enabled, which prompts for username and password after the tunnel is established. These two settings ensure that the VPN can handle dynamic IPs and enforce user authentication. Other settings like Aggressive mode or NAT Traversal may be used but are not required for all scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the 'Remote Gateway' to 'Dialup User'.
Why this is correct
Setting the remote gateway to 'Dialup User' allows the FortiGate to accept connections from any IP address, which is necessary for users with dynamic public IPs. This mode is designed for dial-up VPNs where the remote peer's IP is not known in advance. Without this, the FortiGate would only accept connections from a specific IP.
- ✗
Set the 'Remote Gateway' to the specific IP address of each user.
Why it's wrong here
Setting a specific remote gateway IP is not feasible for users with dynamic public IP addresses. It would require a separate Phase 1 configuration for each user, which is impractical. The correct approach is to use 'Dialup User' to accept connections from any IP, combined with user authentication.
- ✓
Enable 'XAUTH' for extended authentication.
Why this is correct
XAUTH (Extended Authentication) is used in dial-up VPNs to authenticate individual users after the IPsec tunnel is established. It requires users to provide credentials, typically via a pre-shared key or certificate for the tunnel, and then username/password for XAUTH. This ensures that only authorized users can connect, which is essential for a dial-up scenario.
- ✗
Configure 'Aggressive' mode for Phase 1.
Why it's wrong here
Aggressive mode is faster but less secure than Main mode because it exposes the identity of the remote gateway. While it is sometimes used in dial-up VPNs, it is not a requirement and is generally discouraged due to security risks. Main mode is preferred unless there is a specific need for Aggressive mode, such as when the remote gateway has a dynamic IP and the local gateway is static.
- ✗
Enable 'NAT Traversal' in Phase 1 settings.
Why it's wrong here
NAT Traversal is used when there is a NAT device between the VPN peers. While it is often enabled in dial-up VPNs to handle NAT, it is not strictly required for all scenarios. The question asks for required settings to support dynamic IPs and secure authentication; NAT Traversal is beneficial but not mandatory. The essential settings are Dialup User and XAUTH.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.