Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

An administrator has deployed a FortiGate in an SD-WAN hub-and-spoke topology. Spoke sites use IPsec tunnels to the hub, and the hub advertises a default route to the spokes. The administrator wants traffic from any spoke to another spoke to flow through the hub without requiring additional tunnels between spokes. Which SD-WAN feature should be configured on the hub to achieve this?

⚠ Common exam trap

The trap here is assuming that any routing protocol or static route configuration automatically enables spoke-to-spoke communication, when ADVPN's dynamic tunnel negotiation is specifically required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure ADVPN on the hub and spokes, and enable 'set auto-discovery' on the IPsec phase1-interface.

ADVPN enables dynamic spoke-to-spoke tunnels through a hub, allowing traffic to initially flow via the hub and then directly between spokes. Enabling auto-discovery on the IPsec phase1-interface is the key step to activate this behavior. Other options either preserve sessions, add static routes without dynamic tunneling, or configure routing protocols that do not create the necessary overlay shortcuts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'set preserve-session-route' on the hub's SD-WAN zone.

    Why it's wrong here

    This setting preserves session routing for existing sessions when a route changes, but it does not enable spoke-to-spoke traffic forwarding through the hub. It is unrelated to advertising routes or establishing dynamic tunnels, so it would not allow inter-spoke communication in this hub-and-spoke design.

  • ✗

    Enable 'set exchange-interface-ip' on the hub's IPsec tunnels and configure BGP with route reflection.

    Why it's wrong here

    Exchange-interface-ip is used for interface IP exchange in certain VPN scenarios, and BGP route reflection helps with route distribution, but neither directly creates the dynamic spoke-to-spoke tunnels required. The hub would still need to forward traffic, and without ADVPN the spokes cannot establish direct tunnels, so this does not achieve the goal.

  • ✓

    Configure ADVPN on the hub and spokes, and enable 'set auto-discovery' on the IPsec phase1-interface.

    Why this is correct

    ADVPN (Auto-Discovery VPN) allows spokes to dynamically establish direct shortcuts through the hub when traffic between them is detected. By enabling auto-discovery on the hub and spokes, the hub can facilitate spoke-to-spoke tunnels without manual configuration, meeting the requirement for traffic to flow through the hub initially and then directly.

  • ✗

    Create a static route on each spoke pointing to the hub for all remote spoke subnets.

    Why it's wrong here

    Static routes on spokes would direct traffic to the hub, but without a mechanism to establish dynamic tunnels or forward traffic between spokes, the hub would drop packets destined to other spokes. This approach lacks the necessary overlay routing and tunnel negotiation provided by ADVPN, so it fails to enable spoke-to-spoke connectivity.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.