NSE4 Authentication and VPN Practice Question
A FortiGate administrator is configuring a hub-and-spoke IPsec VPN with three spokes. Each spoke has a dial-up connection to the hub. The hub uses a dynamic DNS name. Which THREE settings are necessary on each spoke to establish the VPN?
⚠ Common exam trap
Watch out — candidates often think a static route (Option A) is required for VPN establishment, but routes only direct traffic after the tunnel is up, not for the IKE negotiation itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pre-shared key or certificate for authentication
In a hub-and-spoke IPsec VPN with dial-up spokes, each spoke must authenticate with the hub. The pre-shared key or certificate (Option B) is required for IKE Phase 1 authentication, ensuring the spoke is trusted before the tunnel is established. Without this, the hub will reject the connection attempt.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A static route on the spoke for the hub's local networks
Why it's wrong here
A static route on the spoke for the hub's local networks is unnecessary because the FortiGate hub dynamically advertises those networks to spokes using a routing protocol such as BGP or OSPF over the IPsec tunnel. The spoke only needs a route to the hub's public IP address on its WAN interface to reach the tunnel endpoint. Relying on static routes also creates administrative overhead and can cause routing loops if the hub's networks change.
- ✓
The pre-shared key or certificate for authentication
Why this is correct
The pre-shared key or certificate is a mandatory authentication credential for IKE Phase 1, used by both sides to mutually authenticate before any encryption negotiation occurs. Without a matching PSK or a valid trusted certificate on the spoke, the hub will reject the initial IKE request, and no tunnel can be built. FortiGate supports both PSK and certificate-based authentication, but one must be explicitly configured on the spoke.
- ✓
Hub's public IP address or FQDN as remote gateway
Why this is correct
The spoke must define the hub's public IP address or FQDN as the remote gateway, because that is the destination endpoint for the outbound IKE and IPsec packets. If an FQDN is used, the spoke also needs a DNS server to resolve it; a static IP avoids that dependency. This setting uniquely identifies the hub in the Phase 1 configuration and is a prerequisite for initiating the VPN tunnel.
- ✓
The Phase 2 proposal (encryption, authentication, etc.)
Why this is correct
The Phase 2 proposal specifies the ESP encryption and authentication algorithms, such as AES256/SHA256, that both peers must match exactly to establish an IPsec SA. If the spoke proposes a transform set that differs from the hub's Phase 2 selector, negotiation fails and data is never encrypted. In FortiGate, the Phase 2 configuration also includes the proxy IDs (local/remote subnets), which must align with the hub's policy for traffic to pass.
- ✗
NAT enabled on the spoke tunnel interface
Why it's wrong here
Enabling NAT on the spoke's tunnel interface is not a required or standard part of hub-and-spoke IPsec configuration; in fact, it can break the tunnel by altering the IP headers before encapsulation. FortiGate's default tunnel interface is a point-to-point link without NAT; overlapping-subnet scenarios may use NAT, but that is an optional add-on, not a core requirement. The admin should instead focus on route advertisement and security policies to forward traffic.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.