NSE7 Advanced Networking and SD-WAN Practice Question
An administrator has deployed a FortiGate in an SD-WAN hub-and-spoke topology. Spoke sites use IPsec tunnels to the hub, and the hub advertises a default route to the spokes. The administrator wants traffic from any spoke to another spoke to flow through the hub without requiring additional tunnels between spokes. Which SD-WAN feature should be configured on the hub to achieve this?
⚠ Common exam trap
The trap here is assuming that any routing protocol or static route configuration automatically enables spoke-to-spoke communication, when ADVPN's dynamic tunnel negotiation is specifically required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure ADVPN on the hub and spokes, and enable 'set auto-discovery' on the IPsec phase1-interface.
ADVPN enables dynamic spoke-to-spoke tunnels through a hub, allowing traffic to initially flow via the hub and then directly between spokes. Enabling auto-discovery on the IPsec phase1-interface is the key step to activate this behavior. Other options either preserve sessions, add static routes without dynamic tunneling, or configure routing protocols that do not create the necessary overlay shortcuts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'set preserve-session-route' on the hub's SD-WAN zone.
Why it's wrong here
This setting preserves session routing for existing sessions when a route changes, but it does not enable spoke-to-spoke traffic forwarding through the hub. It is unrelated to advertising routes or establishing dynamic tunnels, so it would not allow inter-spoke communication in this hub-and-spoke design.
- ✗
Enable 'set exchange-interface-ip' on the hub's IPsec tunnels and configure BGP with route reflection.
Why it's wrong here
Exchange-interface-ip is used for interface IP exchange in certain VPN scenarios, and BGP route reflection helps with route distribution, but neither directly creates the dynamic spoke-to-spoke tunnels required. The hub would still need to forward traffic, and without ADVPN the spokes cannot establish direct tunnels, so this does not achieve the goal.
- ✓
Configure ADVPN on the hub and spokes, and enable 'set auto-discovery' on the IPsec phase1-interface.
Why this is correct
ADVPN (Auto-Discovery VPN) allows spokes to dynamically establish direct shortcuts through the hub when traffic between them is detected. By enabling auto-discovery on the hub and spokes, the hub can facilitate spoke-to-spoke tunnels without manual configuration, meeting the requirement for traffic to flow through the hub initially and then directly.
- ✗
Create a static route on each spoke pointing to the hub for all remote spoke subnets.
Why it's wrong here
Static routes on spokes would direct traffic to the hub, but without a mechanism to establish dynamic tunnels or forward traffic between spokes, the hub would drop packets destined to other spokes. This approach lacks the necessary overlay routing and tunnel negotiation provided by ADVPN, so it fails to enable spoke-to-spoke connectivity.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.