Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is configuring an IPsec VPN with IKEv2. The remote peer is behind a NAT device and has a dynamic public IP. The administrator wants the FortiGate to act as the responder and allow the remote peer to initiate the tunnel, while ensuring that only the remote peer's unique ID (FQDN) is accepted. Which configuration on the FortiGate is required to achieve this?

⚠ Common exam trap

The trap here is assuming that the remote gateway must be set to the peer's current IP, but dynamic IPs require 0.0.0.0 to avoid tunnel failures when the IP changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the local gateway to 0.0.0.0 and configure the remote gateway as 0.0.0.0, then set the peer ID to the remote peer's FQDN.

For a remote peer with a dynamic IP behind NAT, the FortiGate must listen on all interfaces and accept connections from any IP. Setting the local gateway to 0.0.0.0 and the remote gateway to 0.0.0.0 enables this. The peer ID is then used to authenticate the remote peer by its FQDN, providing security without relying on a static IP. This configuration is standard for dynamic IP peers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the local gateway to 0.0.0.0 and configure the remote gateway as the remote peer's current public IP, then set the peer ID to the remote peer's FQDN.

    Why it's wrong here

    Configuring a specific remote gateway IP is impractical because the remote peer has a dynamic IP that can change. The FortiGate would lose connectivity when the IP changes. Using 0.0.0.0 for the remote gateway allows any IP, and the peer ID ensures only the correct peer is accepted. This option creates a static dependency on a dynamic IP.

  • ✗

    Set the local gateway to the FortiGate's public IP and configure the remote gateway as 0.0.0.0, then set the peer ID to the remote peer's FQDN.

    Why it's wrong here

    If the local gateway is set to a specific public IP, the FortiGate will only listen on that interface. However, the remote peer's dynamic IP and NAT traversal may require the FortiGate to accept connections on any interface. Additionally, the remote gateway 0.0.0.0 is correct, but the local gateway should be 0.0.0.0 for flexibility. This option restricts the listening interface unnecessarily.

  • ✗

    Set the local gateway to 0.0.0.0 and configure a pre-shared key with the remote peer's FQDN as the peer ID.

    Why it's wrong here

    Setting the local gateway to 0.0.0.0 allows the FortiGate to listen on all interfaces, but the peer ID must be configured on the remote peer's side, not on the FortiGate. The FortiGate needs to match the remote peer's ID using the 'peer-id' setting in the phase 1 configuration. This option misplaces the peer ID configuration.

  • ✓

    Set the local gateway to 0.0.0.0 and configure the remote gateway as 0.0.0.0, then set the peer ID to the remote peer's FQDN.

    Why this is correct

    When the remote peer has a dynamic IP and is behind NAT, the FortiGate must listen on all interfaces (local gateway 0.0.0.0) and accept any remote gateway (remote gateway 0.0.0.0). The peer ID is then used to authenticate the remote peer by its FQDN, ensuring only that peer can connect. This is the correct configuration for dynamic IP with peer ID verification.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.