NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate is configured as a hub in an ADVPN with multiple spokes. The administrator notices that some spokes are not learning routes from other spokes, even though the ADVPN tunnel is up. The hub is using BGP for routing. Which configuration on the hub is required to enable spoke-to-spoke route propagation?
⚠ Common exam trap
Many candidates confuse route reflection with other BGP features like split-horizon or multihop, which do not enable spoke-to-spoke route propagation in ADVPN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the hub as a BGP route reflector and set the spokes as route reflector clients.
For spoke-to-spoke route propagation in ADVPN, the hub must be configured as a BGP route reflector. This allows the hub to reflect routes received from one spoke to other spokes, enabling dynamic tunnel establishment between spokes. Without route reflection, spokes only learn routes from the hub and cannot directly reach other spokes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the hub as a BGP route reflector and set the spokes as route reflector clients.
Why this is correct
In an ADVPN hub-and-spoke topology, the hub must act as a BGP route reflector to propagate routes between spokes. By configuring the hub as a route reflector and the spokes as clients, the hub can reflect routes learned from one spoke to other spokes. This enables spoke-to-spoke communication over dynamic tunnels.
- ✗
Set the hub's BGP router ID to match the IPsec tunnel IP address.
Why it's wrong here
The BGP router ID is used for identification and does not affect route propagation between spokes. While it is good practice to have a unique router ID, matching it to the tunnel IP does not enable spoke-to-spoke route learning. The key is the route reflector configuration, not the router ID.
- ✗
Enable multihop on the hub's BGP peering with the spokes.
Why it's wrong here
Multihop allows BGP sessions to be established across multiple hops, which is useful when peers are not directly connected. However, in a typical ADVPN hub-and-spoke setup, the hub and spokes are directly connected via IPsec tunnels, so multihop is not required. It does not address the need to reflect routes between spokes.
- ✗
Enable split-horizon on the hub's IPsec tunnel interfaces.
Why it's wrong here
Split-horizon is a BGP feature that prevents routes learned from one peer from being advertised back to that same peer. However, it does not enable spoke-to-spoke route propagation. In fact, split-horizon can hinder route propagation in ADVPN if not configured correctly. The hub must be configured to reflect routes between spokes, which is not achieved by split-horizon alone.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.