NSE7 Advanced VPN and Zero Trust Practice Question
A network administrator is configuring an IPsec VPN on a FortiGate to connect to a remote peer that uses a dynamic IP address. The administrator wants to ensure that the tunnel can be initiated by the remote peer and that the FortiGate accepts connections from any IP, as long as the peer ID matches. Which configuration should the administrator use?
⚠ Common exam trap
The trap here is assuming that an FQDN or a specific IP address can handle dynamic IP changes without additional configuration, overlooking the need for 0.0.0.0 and peer ID.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the remote gateway to 0.0.0.0 and configure a peer ID with the remote peer's identifier.
For a remote peer with a dynamic IP, the FortiGate must listen for incoming connections from any IP. Setting the remote gateway to 0.0.0.0 achieves this. The peer ID is then used to uniquely identify and authenticate the remote peer, ensuring that only the legitimate peer can establish the tunnel. This combination is the correct approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a dial-up VPN with a pre-shared key and set the remote gateway to the peer's public IP address.
Why it's wrong here
Setting a specific public IP address for a dynamic peer will fail when the IP changes. A dial-up VPN typically uses 0.0.0.0 for the remote gateway to accept any IP. Specifying the IP defeats the purpose of supporting dynamic addresses and would cause tunnel failures.
- ✓
Set the remote gateway to 0.0.0.0 and configure a peer ID with the remote peer's identifier.
Why this is correct
When the remote peer has a dynamic IP, setting the remote gateway to 0.0.0.0 allows the FortiGate to accept connections from any IP. The peer ID is used to authenticate the remote peer. This is the standard method for dynamic IP peers in IPsec VPN configurations on FortiGate.
- ✗
Configure the remote gateway as a fully qualified domain name (FQDN) and enable dynamic DNS updates.
Why it's wrong here
Using an FQDN requires the remote peer to have a resolvable DNS name that updates dynamically. However, this adds dependency on DNS and may not work if the peer's IP changes without updating DNS. It is less reliable than using 0.0.0.0 with peer ID, and the scenario does not mention DNS.
- ✗
Set the remote gateway to 0.0.0.0 and disable peer ID verification, relying on pre-shared key only.
Why it's wrong here
Disabling peer ID verification reduces security and may allow unauthorized peers to connect if they know the pre-shared key. The scenario specifically requires matching the peer ID, so this configuration would not meet the requirement. It is not the recommended practice for dynamic IP peers.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.