Courseiva
Authentication and VPN →mediumMultiple Select

NSE4 Authentication and VPN Practice Question

An administrator is configuring an IPsec VPN between two FortiGates using IKEv1. The tunnel must use main mode and support multiple subnets behind each gate. Which Phase2 settings are required to allow multiple subnets? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse Phase2 settings (like encryption algorithms or keylife) with the mechanism for defining multiple subnets, leading them to select options that affect security or performance rather than subnet selection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create multiple Phase2 selectors, each with different local and remote subnets

IKEv1 main mode requires that each pair of local and remote subnets be defined in its own Phase2 selector. This allows the VPN to establish separate security associations (SAs) for each subnet pair, enabling multiple subnets behind each FortiGate. Option E is also correct because using address objects that contain multiple subnets (e.g., a subnet group or address range) in a single Phase2 definition is a supported method to negotiate a single SA covering all those subnets, reducing the number of Phase2 selectors needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the Phase2 keylife to a higher value

    Why it's wrong here

    Increasing the Phase2 keylife only changes the SA rekeying interval and has no effect on the traffic selector or the local/remote subnet definitions. The SA still applies to the single, fixed pair of subnets configured in the Phase2 selector. Keylife is a security parameter for key rotation, not a selector attribute, so raising it cannot extend the VPN to protect multiple subnets.

  • ✗

    Set the Phase2 proposal to include multiple encryption algorithms

    Why it's wrong here

    Adding multiple encryption algorithms to a Phase2 proposal broadens the cipher options available during negotiation, but this only affects which algorithms are acceptable for the remote peer. The proxy ID (the negotiated subnet pair) remains a single defined selector, and the algorithm list does not influence the network range that is encrypted. It simply expands cryptographic compatibility, not the scope of subnets in the tunnel.

  • ✓

    Create multiple Phase2 selectors, each with different local and remote subnets

    Why this is correct

    Each Phase2 selector defines exactly one local subnet and one remote subnet pair for a given security association. Creating multiple Phase2 entries under the same Phase1 lets you assign different subnet pairs to the same tunnel, allowing the FortiGate to pick the matching SA for each traffic flow. This is the standard, granular method for supporting multiple subnets across a single IPsec tunnel.

  • ✗

    Enable NAT traversal on the Phase2

    Why it's wrong here

    NAT traversal (NAT-T) is used when IPsec packets pass through devices performing network address translation; it encapsulates ESP in UDP packets and, when needed, adds NAT keepalive mechanisms. It has no relationship to traffic selectors and does not expand or modify the local/remote subnets in the Phase2 definition. Enabling NAT-T only helps if intermediate NAT is present in the path, not to extend subnet coverage.

  • ✓

    Use address objects that contain multiple subnets in the Phase2 definition

    Why this is correct

    A FortiGate address object can represent a list of multiple CIDR subnets (often called a subnet list or group object). When this object is used as the local or remote address in a Phase2 selector, the FortiGate interprets it as an expanded proxy ID, allowing that single Phase2 to cover all the subnets contained in the object. This is a concise way to protect multiple subnets when the same IPsec settings and policies apply to all of them.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.