A network administrator is configuring an IPsec VPN on a FortiGate to connect to a remote peer that uses a dynamic IP address. The administrator wants to ensure that the tunnel can be initiated by the remote peer and that the FortiGate accepts connections from any IP, as long as the peer ID matches. Which configuration should the administrator use?
When the remote peer has a dynamic IP, setting the remote gateway to 0.0.0.0 allows the FortiGate to accept connections from any IP. The peer ID is used to authenticate the remote peer. This is the standard method for dynamic IP peers in IPsec VPN configurations on FortiGate.
Why this answer
For a remote peer with a dynamic IP, the FortiGate must listen for incoming connections from any IP. Setting the remote gateway to 0.0.0.0 achieves this. The peer ID is then used to uniquely identify and authenticate the remote peer, ensuring that only the legitimate peer can establish the tunnel.
This combination is the correct approach.
Exam trap
The trap here is assuming that an FQDN or a specific IP address can handle dynamic IP changes without additional configuration, overlooking the need for 0.0.0.0 and peer ID.