Courseiva
Authentication and VPN →mediumMultiple Select

NSE4 Authentication and VPN Practice Question

A FortiGate administrator is configuring a hub-and-spoke IPsec VPN with three spokes. Each spoke has a dial-up connection to the hub. The hub uses a dynamic DNS name. Which THREE settings are necessary on each spoke to establish the VPN?

⚠ Common exam trap

Watch out — candidates often think a static route (Option A) is required for VPN establishment, but routes only direct traffic after the tunnel is up, not for the IKE negotiation itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The pre-shared key or certificate for authentication

In a hub-and-spoke IPsec VPN with dial-up spokes, each spoke must authenticate with the hub. The pre-shared key or certificate (Option B) is required for IKE Phase 1 authentication, ensuring the spoke is trusted before the tunnel is established. Without this, the hub will reject the connection attempt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A static route on the spoke for the hub's local networks

    Why it's wrong here

    A static route on the spoke for the hub's local networks is unnecessary because the FortiGate hub dynamically advertises those networks to spokes using a routing protocol such as BGP or OSPF over the IPsec tunnel. The spoke only needs a route to the hub's public IP address on its WAN interface to reach the tunnel endpoint. Relying on static routes also creates administrative overhead and can cause routing loops if the hub's networks change.

  • ✓

    The pre-shared key or certificate for authentication

    Why this is correct

    The pre-shared key or certificate is a mandatory authentication credential for IKE Phase 1, used by both sides to mutually authenticate before any encryption negotiation occurs. Without a matching PSK or a valid trusted certificate on the spoke, the hub will reject the initial IKE request, and no tunnel can be built. FortiGate supports both PSK and certificate-based authentication, but one must be explicitly configured on the spoke.

  • ✓

    Hub's public IP address or FQDN as remote gateway

    Why this is correct

    The spoke must define the hub's public IP address or FQDN as the remote gateway, because that is the destination endpoint for the outbound IKE and IPsec packets. If an FQDN is used, the spoke also needs a DNS server to resolve it; a static IP avoids that dependency. This setting uniquely identifies the hub in the Phase 1 configuration and is a prerequisite for initiating the VPN tunnel.

  • ✓

    The Phase 2 proposal (encryption, authentication, etc.)

    Why this is correct

    The Phase 2 proposal specifies the ESP encryption and authentication algorithms, such as AES256/SHA256, that both peers must match exactly to establish an IPsec SA. If the spoke proposes a transform set that differs from the hub's Phase 2 selector, negotiation fails and data is never encrypted. In FortiGate, the Phase 2 configuration also includes the proxy IDs (local/remote subnets), which must align with the hub's policy for traffic to pass.

  • ✗

    NAT enabled on the spoke tunnel interface

    Why it's wrong here

    Enabling NAT on the spoke's tunnel interface is not a required or standard part of hub-and-spoke IPsec configuration; in fact, it can break the tunnel by altering the IP headers before encapsulation. FortiGate's default tunnel interface is a point-to-point link without NAT; overlapping-subnet scenarios may use NAT, but that is an optional add-on, not a core requirement. The admin should instead focus on route advertisement and security policies to forward traffic.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.