NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate administrator is troubleshooting a site-to-site IPsec tunnel that intermittently drops. The administrator runs 'diagnose vpn ike gateway list' and observes that the tunnel re-establishes every few minutes, and 'diagnose debug application ike -1' shows repeated INVALID_KE_PAYLOAD notifications. The remote peer is a third-party gateway that only supports a specific Diffie-Hellman group. What is the most likely cause of the repeated renegotiation?
⚠ Common exam trap
The trap here is interpreting repeated tunnel re-establishment as an authentication or selector problem, when the INVALID_KE_PAYLOAD notification specifically identifies a Diffie-Hellman group mismatch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate phase 1 proposal includes a Diffie-Hellman group that the remote gateway does not support, causing IKE to restart with a different group.
INVALID_KE_PAYLOAD is emitted when the proposed Diffie-Hellman group is unacceptable to the peer, and the initiator then retries with a different group. A third-party gateway restricted to one group will keep rejecting the FortiGate's default proposal, producing the periodic renegotiation. Matching the phase 1 DH group to the remote gateway's supported value fixes the loop.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dead peer detection is configured with an interval shorter than the remote gateway's idle timeout, causing premature tunnel deletion.
Why it's wrong here
Aggressive DPD settings cause tunnels to be torn down based on missed probes, but the debug output would show DPD timeouts or retransmit exhaustion, not INVALID_KE_PAYLOAD. The specific IKE notification observed is tied to Diffie-Hellman negotiation, so adjusting DPD timers would not eliminate the renegotiation loop described.
- ✗
The pre-shared key on the FortiGate does not match the remote gateway, so authentication fails and IKE restarts.
Why it's wrong here
A pre-shared key mismatch produces AUTHENTICATION_FAILED notifications and the tunnel never reaches quick mode. The debug output in this case shows INVALID_KE_PAYLOAD, which occurs earlier during key exchange and indicates a Diffie-Hellman group problem. Changing the pre-shared key would not resolve the observed notification.
- ✗
The phase 2 selectors do not match between peers, so the quick mode negotiation fails and the tunnel is torn down.
Why it's wrong here
Mismatched phase 2 selectors typically produce NO_PROPOSAL_CHOSEN or TS_UNACCEPTABLE notifications and traffic-specific failures, not INVALID_KE_PAYLOAD. The observed notification points to a key exchange problem in phase 1 rather than proxy ID mismatch. Correcting selectors would not address the repeated renegotiation seen in this scenario.
- ✓
The FortiGate phase 1 proposal includes a Diffie-Hellman group that the remote gateway does not support, causing IKE to restart with a different group.
Why this is correct
INVALID_KE_PAYLOAD is the standard IKE notification sent when the responder cannot accept the proposed Diffie-Hellman group, prompting the initiator to retry with another group. Repeated renegotiation every few minutes indicates the FortiGate keeps offering a group the third-party gateway rejects. Aligning the phase 1 DH group with the remote gateway's supported group resolves the mismatch and stabilizes the tunnel.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.