Courseiva
Advanced VPN and Zero Trust →mediumMultiple Choice

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is configuring an IPsec VPN tunnel to a remote site that is behind a NAT device. The administrator notices that the tunnel establishes, but traffic intermittently fails. Which setting should be adjusted to improve reliability?

⚠ Common exam trap

The trap here is attributing intermittent failures to DPD or encryption settings, when the root cause is often NAT session timeout that can be mitigated with NAT-T and keepalives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable NAT traversal (NAT-T) and set the keepalive frequency.

When an IPsec peer is behind NAT, the NAT device may close the UDP session if no traffic is sent for a period. Enabling NAT traversal (NAT-T) encapsulates IPsec packets in UDP, and setting a keepalive frequency ensures that periodic packets are sent to keep the NAT mapping alive. This prevents intermittent tunnel failures caused by NAT session timeouts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Dead Peer Detection (DPD) with a shorter interval.

    Why it's wrong here

    DPD is used to detect dead peers, but it does not address intermittent traffic failures caused by NAT. While a shorter DPD interval can help detect failures faster, it does not solve the underlying NAT traversal issue that causes the intermittent failures. DPD is more about failure detection than prevention.

  • ✗

    Configure the remote gateway as a dynamic DNS hostname.

    Why it's wrong here

    Using a dynamic DNS hostname helps when the remote peer's IP changes, but it does not solve intermittent failures caused by NAT. If the peer is behind NAT with a stable public IP, dynamic DNS is not necessary. The issue is likely NAT session timeout, which requires NAT-T and keepalives.

  • ✓

    Enable NAT traversal (NAT-T) and set the keepalive frequency.

    Why this is correct

    NAT traversal (NAT-T) encapsulates IPsec packets in UDP to allow them to pass through NAT devices. The keepalive frequency setting sends periodic keepalive packets to maintain the NAT mapping and prevent the NAT session from timing out. This is crucial for reliability when a peer is behind NAT, as it keeps the UDP port open and avoids intermittent failures due to NAT session expiration.

  • ✗

    Set the IPsec phase-1 proposal to use AES-256 encryption.

    Why it's wrong here

    Changing the encryption algorithm to AES-256 does not affect NAT traversal or reliability. While AES-256 is strong encryption, it does not address the NAT-related issues that cause intermittent traffic failures. The problem is not about encryption strength but about maintaining the NAT mapping.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.