Courseiva
Security Profiles Routing And IPsecmediumMultiple ChoiceObjective-mapped

NSE7_SDW Security Profiles Routing And IPsec Practice Question

An administrator configures an ADVPN 2.0 deployment between a FortiGate hub and multiple spokes using OSPF as the dynamic routing protocol. The spoke units need to establish direct shortcut tunnels dynamically. Which configuration step is mandatory on the hub to ensure that BGP or OSPF next-hop resolution works correctly for ADVPN shortcut creation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable next-hop-self on the hub's BGP neighbor configuration or adjust OSPF interface settings so the advertising router is not forced as the next hop

In ADVPN environments running dynamic routing protocols like OSPF or BGP, network-object settings or interface settings such as setting the route-map or disabling next-hop-self on the hub allow spokes to properly resolve shortcut routes. Specifically, modifying the BGP next-hop or OSPF next-hop behavior ensures traffic is steered directly to the requesting spoke's IP rather than looping back through the hub.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable split-horizon globally within the OSPF routing process

    Why it's wrong here

    Split-horizon is typically disabled or managed via non-broadcast multi-access (NBMA) settings in ADVPN, not globally toggled for this purpose.

  • Disable next-hop-self on the hub's BGP neighbor configuration or adjust OSPF interface settings so the advertising router is not forced as the next hop

    Why this is correct

    Correct. By default, protocols like BGP use next-hop-self which forces traffic through the hub, breaking ADVPN shortcut creation unless properly configured to preserve the originating peer's IP or using shortcut-specific routing policies.

  • Enable exchange-interface in the hub's OSPF interface configuration

    Why it's wrong here

    Exchange-interface is not a standard FortiOS OSPF configuration command for ADVPN.

  • Configure a static blackhole route for all spoke subnets on the hub

    Why it's wrong here

    A blackhole route would drop traffic destined for the spokes.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

About these practice questions

One of 92 original NSE7_SDW practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Fortinet exam blueprint

This NSE7_SDW practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7_SDW exam.