NSE4 Authentication and VPN Practice Question
Which IPsec VPN mode uses IP addresses and ports to define interesting traffic, and requires a separate security policy for each tunnel?
⚠ Common exam trap
A common mix-up: candidates confuse 'policy-based VPN' with 'route-based VPN', mistakenly thinking that route-based VPNs require separate security policies per tunnel, when in fact route-based VPNs use a single policy tied to the IPsec interface and leverage routing to handle multiple destinations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy-based VPN
Policy-based VPN (B) is correct because it defines interesting traffic using source/destination IP addresses and ports, and each tunnel requires a separate security policy to specify which traffic should be encrypted. This contrasts with route-based VPNs, which use virtual interfaces and routing tables to determine traffic, allowing a single policy to handle multiple tunnels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hub-and-spoke VPN
Why it's wrong here
Hub-and-spoke VPN describes a common topology in which multiple remote sites connect to a central hub, but it is not an IPsec mode that selects traffic by IP addresses and ports. Traffic selection in a hub-and-spoke deployment still depends on either policy-based or route-based configuration. Therefore, it cannot be the correct answer to a question about traffic-defining modes.
- ✓
Policy-based VPN
Why this is correct
Policy-based VPN is the correct IPsec mode because it uses firewall policies to define interesting traffic by matching source/destination IP addresses, protocols, and ports, and then applies action 'IPsec' to encrypt that traffic. In FortiGate, the policy also references the IPsec phase1/phase2 VPN tunnel and security profiles, making the policy the single point of traffic selection. This is exactly how addresses and ports determine which traffic goes over the VPN.
- ✗
Dial-up VPN
Why it's wrong here
Dial-up VPN refers to a scenario where remote clients initiate a VPN connection on demand, often receiving dynamic IP addresses from the FortiGate via mode-config, rather than a mode that defines interesting traffic by IP and port. While dial-up deployments may use firewall policies for traffic matching, the term itself describes the client-initiated call setup and tunnel negotiation, not the address/port-based traffic selection mechanism. Thus it is not the mode asked about.
- ✗
Route-based VPN
Why it's wrong here
Route-based VPN is a mode that establishes an IPsec tunnel interface and selects interesting traffic through the routing table and source/destination routes, not by matching addresses and ports in a firewall policy. Because the tunnel behaves as an overlay network interface, no policy with IPsec action is needed; instead, routes are configured to direct traffic into the virtual interface. This is the opposite characteristic of using IP addresses and ports for traffic definition.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.