Courseiva
Authentication and VPN →hardMultiple Select

NSE4 Authentication and VPN Practice Question

Which TWO are best practices for configuring IPsec VPN on FortiGate to ensure high availability and security?

⚠ Common exam trap

Many exam-takers confuse DPD with a performance overhead feature and disable it, or they mistakenly believe aggressive mode is faster and therefore better, overlooking the severe security implications of sending identities in cleartext.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable perfect forward secrecy (PFS) for phase2 to ensure session keys are not compromised if a private key is stolen.

Perfect Forward Secrecy (PFS) ensures that if an attacker compromises the private key used during IKE phase1, they cannot derive the session keys used in phase2. By requiring a new Diffie-Hellman exchange for each phase2 rekey, PFS isolates the compromise to only the current session, protecting past and future encrypted traffic. This is a critical security best practice for IPsec VPNs on FortiGate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable DPD on the phase1 interface to reduce overhead.

    Why it's wrong here

    Disabling DPD on the phase1 interface to reduce overhead is wrong because DPD probes are only sent when the tunnel has no recent traffic, so the extra control message overhead is negligible. Without DPD, the firewall cannot detect when a remote peer is dead, causing traffic to be black-holed until the IKE SA lifetime expires or manual intervention occurs. Best practice is to enable DPD with a reasonable retry interval so the tunnel fails over as soon as peer loss occurs.

  • ✓

    Enable perfect forward secrecy (PFS) for phase2 to ensure session keys are not compromised if a private key is stolen.

    Why this is correct

    Enabling PFS for phase2 is a best practice because it forces a new Diffie-Hellman exchange for each Quick Mode, generating fresh session keys independent of the IKE SA's shared secret. If the firewall's private key or pre-shared secret is later stolen, an attacker cannot use it to derive previous or subsequent phase2 keys, limiting data exposure to the current session. PFS adds a small computational cost but is strongly recommended for environments handling sensitive data.

  • ✗

    Use aggressive mode for faster IKE negotiation.

    Why it's wrong here

    Using aggressive mode in IKEv1 for faster negotiation is not a recommended practice because it sends the identity payload and hash in the second exchange without encryption, allowing an attacker to perform offline dictionary attacks on weak pre-shared keys. Main mode protects the identity by encrypting it after an authenticated Diffie-Hellman exchange, making it the secure default. If performance is a concern, prefer IKEv2, which provides improved reliability and security without aggressive-mode weaknesses.

  • ✓

    Configure a dead peer detection (DPD) interval to detect tunnel failures.

    Why this is correct

    Configuring a dead peer detection (DPD) interval is a best practice because it allows the firewall to quickly identify when a remote VPN peer becomes unreachable, avoiding prolonged outages and routing over dead tunnels. FortiGate's DPD implementation (RFC 3706) sends a small phase1 notify payload and waits for a corresponding R-U-THERE-II response; if no reply is received after the configured retry count, the tunnel is declared down and traffic can be redirected. Set the interval conservatively (e.g., 5-30 seconds) to balance detection speed against bandwidth usage.

  • ✗

    Disable PFS to reduce CPU load on the firewall.

    Why it's wrong here

    Disabling PFS to reduce CPU load on the firewall is not a best practice because it increases security risk: without PFS, phase2 session keys are derived directly from the IKE SA's Diffie-Hellman result, so compromising the long-term private key compromises all current and future session keys. The CPU overhead of performing an additional DH exchange per phase2 rekey is negligible on modern FortiGate hardware, and the security benefit far outweighs any minor performance impact. Hence PFS should remain enabled for all phase2 negotiations.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.