Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

A FortiGate is configured as a hub in a hub-and-spoke IPsec VPN. The spokes are remote branches. The hub has a Phase 2 selector set to 0.0.0.0/0 for both local and remote subnets. What is the advantage of this configuration?

⚠ Common exam trap

NSE4 often tests the misconception that a 0.0.0.0/0 Phase 2 selector enables spoke-to-spoke direct communication or dynamic routing, when it actually only simplifies hub configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It simplifies configuration by not needing specific subnet definitions per spoke

Using 0.0.0.0/0 as the Phase 2 selector on the hub allows the hub to accept any remote subnet from any spoke without defining each spoke's specific subnet in the Phase 2 configuration. This dramatically simplifies hub configuration in a hub-and-spoke topology because new spokes can be added without modifying the hub's Phase 2 selectors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It reduces the number of IPsec SAs needed

    Why it's wrong here

    This is incorrect. In a hub-and-spoke VPN, each spoke establishes its own IPsec tunnel with the hub, and every tunnel requires its own set of Phase 2 SAs (one per direction) regardless of whether the Phase 2 selector is a specific subnet or 0.0.0.0/0. The broad selector only means one Phase 2 SA on a given tunnel can cover traffic for multiple subnets at that spoke; it does not collapse the per-spoke SA pairs into a single SA. The total number of SAs is driven by the number of active spoke peers, not by the width of the proxy ID.

  • ✓

    It simplifies configuration by not needing specific subnet definitions per spoke

    Why this is correct

    This is correct. Configuring the Phase 2 selector as 0.0.0.0/0 on the hub means the hub will accept any source and destination subnet from the spoke during Phase 2 negotiation, so there is no need to define each spoke's LAN subnets explicitly. When a spoke adds, removes, or changes a protected subnet behind it, the hub's Phase 2 configuration remains valid and no reconfiguration is required. This greatly simplifies hub management in a dynamic environment where spoke subnets are not stable or are unknown in advance.

  • ✗

    It allows direct spoke-to-spoke communication without passing through the hub

    Why it's wrong here

    This is incorrect. Even with a 0.0.0.0/0 Phase 2 selector, spoke-to-spoke traffic must still pass through the hub because each spoke only has a single IPsec peer — the hub — and no direct tunnel exists between spokes. The hub receives the encrypted packet from one spoke, decrypts it, examines the destination, re-encrypts it with the SA for the destination spoke, and forwards it; this is normal hub-and-spoke forwarding. A 0.0.0.0/0 selector only controls which traffic can be encrypted on a given tunnel, not the topology or routing path.

  • ✗

    It enables dynamic routing protocols over the VPN

    Why it's wrong here

    This is incorrect. Phase 2 selectors (proxy IDs) determine which IP traffic is protected by an IPsec SA; they have no effect on whether dynamic routing protocols such as OSPF or BGP can run over the tunnel. To use dynamic routing, you must configure the routing protocol on the tunnel interface (or over the VPN virtual interface), define appropriate neighbors and policy routes, and in many cases enable additional settings such as mode-config or interface mode. The 0.0.0.0/0 selector simply tells the gateway that all subnets are interesting traffic; it does not enable or disable routing processes.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.