NSE7 Advanced VPN and Zero Trust Practice Question
An administrator is building an ADVPN with a single hub and many spokes. Spokes are behind NAT devices and receive dynamic public IP addresses. The administrator wants shortcuts to form directly between spokes without routing traffic through the hub. Which combination of features must be configured on the hub and spokes to allow shortcut negotiation to succeed in this environment?
⚠ Common exam trap
The trap here is believing that ADVPN shortcuts are negotiated by the hub on behalf of the spokes, when in fact the hub only relays auto-discovery messages and each spoke pair builds its own tunnel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure IKEv2 with auto-discovery sender and receiver, and enable NAT traversal on all participating FortiGates.
ADVPN relies on IKEv2 auto-discovery to propagate shortcut offers from spoke to spoke through the hub, and on NAT traversal to keep IKE and ESP reachable across NAT devices. With auto-discovery sender and receiver roles configured and NAT traversal enabled, spokes with dynamic addresses can negotiate direct tunnels. Static addressing or unrelated interface features do not substitute for this signalling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure IKEv2 with auto-discovery sender and receiver, and enable NAT traversal on all participating FortiGates.
Why this is correct
ADVPN shortcut negotiation uses IKEv2 auto-discovery sender and receiver roles to exchange shortcut offers and replies between spokes, while NAT traversal keeps the IKE and ESP traffic flowing through intervening NAT devices. Together these allow spokes with dynamic, NATed addresses to learn each other's reachable endpoints and build direct tunnels, which is precisely what the design requires.
- ✗
Enable IPsec aggregate interfaces and set net-device disable on all tunnel interfaces.
Why it's wrong here
Aggregate IPsec interfaces bundle multiple tunnels into one logical interface for bandwidth, but they do not perform shortcut negotiation between spokes. Disabling net-device changes how tunnel interface addressing is handled and does not provide the NAT traversal or shortcut signalling needed. This combination would leave spoke-to-spoke traffic hairpinning through the hub rather than forming direct shortcuts as intended.
- ✗
Enable exchange-interface-ip and set mode-cfg on the spokes while disabling DPD on the hub.
Why it's wrong here
Exchange-interface-ip and mode-cfg affect interface addressing and IKE configuration payload handling, but they are not the mechanism that negotiates shortcuts between spokes. Disabling DPD on the hub would actually harm failure detection and shortcut maintenance. This set of changes does not provide the auto-discovery signalling or NAT traversal required for direct spoke-to-spoke tunnels.
- ✗
Set the hub as a dial-up server and configure the spokes with static VIP addresses on the NAT devices.
Why it's wrong here
Requiring static VIPs on the NAT devices contradicts the scenario, where spokes have dynamic public addresses and cannot publish a fixed endpoint. Dial-up server configuration on the hub is normal for ADVPN, but it does not by itself create spoke-to-spoke shortcuts. This approach would not scale to many NATed spokes and would not enable direct shortcut formation.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.