Courseiva
Advanced VPN and Zero TrusthardMultiple SelectObjective-mapped

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate administrator is configuring OSPF over an IPsec VPN overlay in a hub-and-spoke topology. The spokes have dynamic IPs and use ADVPN. Which THREE conditions are necessary for OSPF to work correctly over the VPN tunnels?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The OSPF router ID must be unique across all spokes

OSPF requires stable network types and correct interface configuration. For ADVPN, OSPF should use point-to-point network type to avoid DR elections and ensure proper neighbor relationships.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The OSPF router ID must be unique across all spokes

    Why this is correct

    OSPF router IDs must be unique to prevent routing issues.

  • The OSPF hello interval must be less than the DPD retry interval

    Why it's wrong here

    No direct relationship; both can be tuned independently.

  • The hub must have all spoke routes in its routing table before OSPF starts

    Why it's wrong here

    OSPF will learn routes dynamically; pre-populated routes are not necessary.

  • The tunnel interfaces must have an IP address configured

    Why this is correct

    OSPF requires an IP address on the interface to form adjacencies.

  • The OSPF network type on the tunnel interfaces must be set to point-to-point

    Why this is correct

    Point-to-point avoids DR/BDR elections and works well with VPN tunnels.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.