NSE7 Advanced VPN and Zero Trust Practice Question
A FortiGate is configured with multiple IPsec VPNs to remote branches. One of the branch VPN tunnels goes down frequently. The administrator runs 'diagnose vpn ike log' and sees repeated INITIAL_CONTACT notifications from the remote peer. What does this indicate?
⚠ Common exam trap
NSE7 often tests the distinction between IKE notification types, so candidates confuse INITIAL_CONTACT with rekey or DPD events and pick the wrong cause of tunnel flapping.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The remote peer has rebooted or restarted its VPN service
An INITIAL_CONTACT notification is sent by an IKE peer when it establishes a new IKE SA and wants the remote peer to delete any existing IKE SAs associated with the same identity. This is standard behavior after a reboot, VPN service restart, or when the peer loses its state and re-initiates from scratch. Repeated INITIAL_CONTACT messages therefore indicate the remote branch device is repeatedly restarting or flapping its VPN daemon, not a normal rekey or DPD event.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The remote peer is rekeying the VPN tunnel
Why it's wrong here
Rekeying is negotiated with CREATE_CHILD_SA exchanges within the existing IKE security association, whereas INITIAL_CONTACT signals a fresh phase 1 with no prior state. It is tempting because rekey failures do cause tunnels to drop, and it would be correct if the log showed rekey or CREATE_CHILD_SA messages rather than a new initial exchange.
- ✗
The local FortiGate has a mismatched pre-shared key
Why it's wrong here
A mismatched pre-shared key causes IKE phase 1 to fail outright, so the tunnel never establishes; repeated INITIAL_CONTACT instead shows the peer re-establishing an existing security association. It is tempting because key mismatch is a common cause of flapping tunnels, and it would be correct if the log showed NO_PROPOSAL_CHOSEN or authentication failures.
- ✗
A dead peer detection timeout occurred
Why it's wrong here
Dead peer detection produces DPD timeout or retransmission entries in the IKE log, not INITIAL_CONTACT, which the peer sends when it believes no prior IKE session exists. It is tempting because DPD commonly explains flapping tunnels, and it would be correct where the log shows DPD timeouts against an otherwise established phase 1.
- ✓
The remote peer has rebooted or restarted its VPN service
Why this is correct
INITIAL_CONTACT is sent when an IKE peer starts without existing security associations, so repeated notifications mean the branch device or its VPN daemon is restarting, tearing down and renegotiating the tunnel. This directly explains the frequent outages observed on that branch VPN.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.