Courseiva
Advanced VPN and Zero Trust →mediumMultiple Select

NSE7 Advanced VPN and Zero Trust Practice Question

A network administrator is troubleshooting a scenario where remote users can connect via FortiClient VPN but cannot access internal resources. The FortiGate has a valid IPsec VPN configuration. Which THREE checks should the administrator perform to resolve the issue?

⚠ Common exam trap

The trap here is that candidates often focus on tunnel-level settings like MTU or DPD when the real issue is a missing return route or firewall policy, which are common misconfigurations in IPsec VPN deployments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check if there is a route on the internal network pointing back to the VPN subnet

Option A is correct because remote-access IPsec VPN clients use a virtual IP pool subnet, and internal hosts or routers must have a return route for that VPN subnet; without it, return traffic is dropped and users cannot reach internal resources even though the tunnel is up. Option B is correct because NAT must be disabled on the VPN policy; if NAT is enabled, the FortiGate translates the source address of VPN traffic, which breaks routing and access to internal resources that expect the original VPN pool address. Option E is correct because the FortiGate requires an explicit firewall policy permitting traffic from the VPN IP pool (source) to the internal network (destination), and without this policy the tunnel establishes but no traffic is allowed through. Option C is not appropriate because increasing MTU on the VPN interface is not a standard fix for access failures and can worsen fragmentation issues; MTU problems typically require lowering or adjusting MSS, not raising MTU. Option D is not appropriate because disabling Dead Peer Detection (DPD) on phase 1 does not resolve internal resource access problems and can prevent the FortiGate from detecting dead VPN peers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check if there is a route on the internal network pointing back to the VPN subnet

    Why this is correct

    The internal hosts must know how to reach the VPN client subnet. Without a return route pointing back to the VPN IP pool, replies are dropped or sent to the default gateway, so traffic never returns to the tunnel.

  • ✓

    Ensure that NAT is disabled on the VPN policy

    Why this is correct

    Disabling NAT on the IPsec VPN policy preserves the original source IP addresses from remote clients, allowing return traffic to route correctly to internal resources. If NAT were enabled, internal servers would reply to the FortiGate's interface address rather than the tunnel, breaking connectivity for users who authenticate successfully but cannot reach protected subnets.

  • ✗

    Increase the MTU on the VPN interface

    Why it's wrong here

    MTU issues cause fragmentation but not complete lack of connectivity.

  • ✗

    Disable DPD on the VPN phase 1

    Why it's wrong here

    DPD is for dead peer detection, not access.

  • ✓

    Verify that the firewall policy allows traffic from the VPN IP pool to the internal network

    Why this is correct

    Even with a valid tunnel, FortiGate only forwards traffic permitted by policy. A firewall policy must explicitly allow traffic from the VPN IP pool to the internal network, otherwise packets are denied despite successful connection.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.