NSE4 Authentication and VPN Practice Question
Which TWO are best practices for configuring IPsec VPN on FortiGate to ensure high availability and security?
⚠ Common exam trap
Many exam-takers confuse DPD with a performance overhead feature and disable it, or they mistakenly believe aggressive mode is faster and therefore better, overlooking the severe security implications of sending identities in cleartext.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable perfect forward secrecy (PFS) for phase2 to ensure session keys are not compromised if a private key is stolen.
Perfect Forward Secrecy (PFS) ensures that if an attacker compromises the private key used during IKE phase1, they cannot derive the session keys used in phase2. By requiring a new Diffie-Hellman exchange for each phase2 rekey, PFS isolates the compromise to only the current session, protecting past and future encrypted traffic. This is a critical security best practice for IPsec VPNs on FortiGate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable DPD on the phase1 interface to reduce overhead.
Why it's wrong here
Disabling DPD on the phase1 interface to reduce overhead is wrong because DPD probes are only sent when the tunnel has no recent traffic, so the extra control message overhead is negligible. Without DPD, the firewall cannot detect when a remote peer is dead, causing traffic to be black-holed until the IKE SA lifetime expires or manual intervention occurs. Best practice is to enable DPD with a reasonable retry interval so the tunnel fails over as soon as peer loss occurs.
- ✓
Enable perfect forward secrecy (PFS) for phase2 to ensure session keys are not compromised if a private key is stolen.
Why this is correct
Enabling PFS for phase2 is a best practice because it forces a new Diffie-Hellman exchange for each Quick Mode, generating fresh session keys independent of the IKE SA's shared secret. If the firewall's private key or pre-shared secret is later stolen, an attacker cannot use it to derive previous or subsequent phase2 keys, limiting data exposure to the current session. PFS adds a small computational cost but is strongly recommended for environments handling sensitive data.
- ✗
Use aggressive mode for faster IKE negotiation.
Why it's wrong here
Using aggressive mode in IKEv1 for faster negotiation is not a recommended practice because it sends the identity payload and hash in the second exchange without encryption, allowing an attacker to perform offline dictionary attacks on weak pre-shared keys. Main mode protects the identity by encrypting it after an authenticated Diffie-Hellman exchange, making it the secure default. If performance is a concern, prefer IKEv2, which provides improved reliability and security without aggressive-mode weaknesses.
- ✓
Configure a dead peer detection (DPD) interval to detect tunnel failures.
Why this is correct
Configuring a dead peer detection (DPD) interval is a best practice because it allows the firewall to quickly identify when a remote VPN peer becomes unreachable, avoiding prolonged outages and routing over dead tunnels. FortiGate's DPD implementation (RFC 3706) sends a small phase1 notify payload and waits for a corresponding R-U-THERE-II response; if no reply is received after the configured retry count, the tunnel is declared down and traffic can be redirected. Set the interval conservatively (e.g., 5-30 seconds) to balance detection speed against bandwidth usage.
- ✗
Disable PFS to reduce CPU load on the firewall.
Why it's wrong here
Disabling PFS to reduce CPU load on the firewall is not a best practice because it increases security risk: without PFS, phase2 session keys are derived directly from the IKE SA's Diffie-Hellman result, so compromising the long-term private key compromises all current and future session keys. The CPU overhead of performing an additional DH exchange per phase2 rekey is negligible on modern FortiGate hardware, and the security benefit far outweighs any minor performance impact. Hence PFS should remain enabled for all phase2 negotiations.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.