NSE4 Authentication and VPN Practice Question
An administrator is configuring an IPsec VPN between two FortiGates using IKEv1. The tunnel must use main mode and support multiple subnets behind each gate. Which Phase2 settings are required to allow multiple subnets? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse Phase2 settings (like encryption algorithms or keylife) with the mechanism for defining multiple subnets, leading them to select options that affect security or performance rather than subnet selection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create multiple Phase2 selectors, each with different local and remote subnets
IKEv1 main mode requires that each pair of local and remote subnets be defined in its own Phase2 selector. This allows the VPN to establish separate security associations (SAs) for each subnet pair, enabling multiple subnets behind each FortiGate. Option E is also correct because using address objects that contain multiple subnets (e.g., a subnet group or address range) in a single Phase2 definition is a supported method to negotiate a single SA covering all those subnets, reducing the number of Phase2 selectors needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the Phase2 keylife to a higher value
Why it's wrong here
Increasing the Phase2 keylife only changes the SA rekeying interval and has no effect on the traffic selector or the local/remote subnet definitions. The SA still applies to the single, fixed pair of subnets configured in the Phase2 selector. Keylife is a security parameter for key rotation, not a selector attribute, so raising it cannot extend the VPN to protect multiple subnets.
- ✗
Set the Phase2 proposal to include multiple encryption algorithms
Why it's wrong here
Adding multiple encryption algorithms to a Phase2 proposal broadens the cipher options available during negotiation, but this only affects which algorithms are acceptable for the remote peer. The proxy ID (the negotiated subnet pair) remains a single defined selector, and the algorithm list does not influence the network range that is encrypted. It simply expands cryptographic compatibility, not the scope of subnets in the tunnel.
- ✓
Create multiple Phase2 selectors, each with different local and remote subnets
Why this is correct
Each Phase2 selector defines exactly one local subnet and one remote subnet pair for a given security association. Creating multiple Phase2 entries under the same Phase1 lets you assign different subnet pairs to the same tunnel, allowing the FortiGate to pick the matching SA for each traffic flow. This is the standard, granular method for supporting multiple subnets across a single IPsec tunnel.
- ✗
Enable NAT traversal on the Phase2
Why it's wrong here
NAT traversal (NAT-T) is used when IPsec packets pass through devices performing network address translation; it encapsulates ESP in UDP packets and, when needed, adds NAT keepalive mechanisms. It has no relationship to traffic selectors and does not expand or modify the local/remote subnets in the Phase2 definition. Enabling NAT-T only helps if intermediate NAT is present in the path, not to extend subnet coverage.
- ✓
Use address objects that contain multiple subnets in the Phase2 definition
Why this is correct
A FortiGate address object can represent a list of multiple CIDR subnets (often called a subnet list or group object). When this object is used as the local or remote address in a Phase2 selector, the FortiGate interprets it as an expanded proxy ID, allowing that single Phase2 to cover all the subnets contained in the object. This is a concise way to protect multiple subnets when the same IPsec settings and policies apply to all of them.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.