NSE7 Advanced VPN and Zero Trust Practice Question
A network administrator is setting up an IPsec VPN between two FortiGates. The administrator wants to ensure that if the VPN tunnel goes down, the FortiGate can automatically re-establish it without manual intervention. Which IPsec feature should the administrator enable to detect peer failures and trigger tunnel renegotiation?
⚠ Common exam trap
Watch out — candidates often confuse security features like PFS or fragmentation with the liveness detection provided by DPD.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dead Peer Detection (DPD) with the mode set to on-idle or always.
Dead Peer Detection is the IPsec mechanism that monitors peer liveness by sending probes or waiting for idle periods. When the peer fails to respond, DPD marks the tunnel as down and triggers renegotiation or failover. Setting DPD mode to on-idle or always ensures continuous monitoring, enabling automatic tunnel recovery without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Dead Peer Detection (DPD) with the mode set to on-idle or always.
Why this is correct
DPD is the IPsec feature that detects when a peer becomes unreachable. When enabled, the FortiGate sends periodic probes or waits for idle traffic before probing. If the peer fails to respond, DPD marks the tunnel as down and triggers renegotiation or failover. Setting DPD mode to on-idle or always ensures detection occurs and the tunnel can be automatically re-established without manual intervention.
- ✗
Automatic Key Negotiation (AutoIKE) to dynamically negotiate new SAs.
Why it's wrong here
There is no FortiGate feature called Automatic Key Negotiation or AutoIKE for this purpose. IKE itself negotiates SAs, but it does not independently detect peer failures. DPD is the mechanism that monitors peer liveness and triggers renegotiation. AutoIKE is not a valid FortiGate configuration option, so it cannot be used to detect peer failures and automatically re-establish the tunnel.
- ✗
Perfect Forward Secrecy (PFS) to generate new keys for each phase 2 negotiation.
Why it's wrong here
PFS ensures that compromise of one key does not compromise previous or future keys by generating new keys during phase 2. It enhances security but does not detect peer failures or trigger renegotiation. The tunnel could remain down if the peer is unreachable, regardless of PFS. Therefore, PFS does not satisfy the requirement for automatic failure detection and re-establishment.
- ✗
IKEv2 fragmentation to allow large packets to traverse the tunnel.
Why it's wrong here
IKEv2 fragmentation addresses issues with large IKE packets being dropped by intermediate devices. It does not detect peer failures or trigger tunnel renegotiation. While useful for interoperability, it is not the feature that monitors peer availability. DPD is specifically designed for failure detection, so IKEv2 fragmentation does not meet the requirement of automatic tunnel re-establishment after a peer failure.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.