Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

A FortiGate is configured with multiple IPsec VPNs to remote branches. One of the branch VPN tunnels goes down frequently. The administrator runs 'diagnose vpn ike log' and sees repeated INITIAL_CONTACT notifications from the remote peer. What does this indicate?

⚠ Common exam trap

NSE7 often tests the distinction between IKE notification types, so candidates confuse INITIAL_CONTACT with rekey or DPD events and pick the wrong cause of tunnel flapping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The remote peer has rebooted or restarted its VPN service

An INITIAL_CONTACT notification is sent by an IKE peer when it establishes a new IKE SA and wants the remote peer to delete any existing IKE SAs associated with the same identity. This is standard behavior after a reboot, VPN service restart, or when the peer loses its state and re-initiates from scratch. Repeated INITIAL_CONTACT messages therefore indicate the remote branch device is repeatedly restarting or flapping its VPN daemon, not a normal rekey or DPD event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The remote peer is rekeying the VPN tunnel

    Why it's wrong here

    Rekeying is negotiated with CREATE_CHILD_SA exchanges within the existing IKE security association, whereas INITIAL_CONTACT signals a fresh phase 1 with no prior state. It is tempting because rekey failures do cause tunnels to drop, and it would be correct if the log showed rekey or CREATE_CHILD_SA messages rather than a new initial exchange.

  • ✗

    The local FortiGate has a mismatched pre-shared key

    Why it's wrong here

    A mismatched pre-shared key causes IKE phase 1 to fail outright, so the tunnel never establishes; repeated INITIAL_CONTACT instead shows the peer re-establishing an existing security association. It is tempting because key mismatch is a common cause of flapping tunnels, and it would be correct if the log showed NO_PROPOSAL_CHOSEN or authentication failures.

  • ✗

    A dead peer detection timeout occurred

    Why it's wrong here

    Dead peer detection produces DPD timeout or retransmission entries in the IKE log, not INITIAL_CONTACT, which the peer sends when it believes no prior IKE session exists. It is tempting because DPD commonly explains flapping tunnels, and it would be correct where the log shows DPD timeouts against an otherwise established phase 1.

  • ✓

    The remote peer has rebooted or restarted its VPN service

    Why this is correct

    INITIAL_CONTACT is sent when an IKE peer starts without existing security associations, so repeated notifications mean the branch device or its VPN daemon is restarting, tearing down and renegotiating the tunnel. This directly explains the frequent outages observed on that branch VPN.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.