Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator is building an ADVPN with a single hub and many spokes. Spokes are behind NAT devices and receive dynamic public IP addresses. The administrator wants shortcuts to form directly between spokes without routing traffic through the hub. Which combination of features must be configured on the hub and spokes to allow shortcut negotiation to succeed in this environment?

⚠ Common exam trap

The trap here is believing that ADVPN shortcuts are negotiated by the hub on behalf of the spokes, when in fact the hub only relays auto-discovery messages and each spoke pair builds its own tunnel.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure IKEv2 with auto-discovery sender and receiver, and enable NAT traversal on all participating FortiGates.

ADVPN relies on IKEv2 auto-discovery to propagate shortcut offers from spoke to spoke through the hub, and on NAT traversal to keep IKE and ESP reachable across NAT devices. With auto-discovery sender and receiver roles configured and NAT traversal enabled, spokes with dynamic addresses can negotiate direct tunnels. Static addressing or unrelated interface features do not substitute for this signalling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure IKEv2 with auto-discovery sender and receiver, and enable NAT traversal on all participating FortiGates.

    Why this is correct

    ADVPN shortcut negotiation uses IKEv2 auto-discovery sender and receiver roles to exchange shortcut offers and replies between spokes, while NAT traversal keeps the IKE and ESP traffic flowing through intervening NAT devices. Together these allow spokes with dynamic, NATed addresses to learn each other's reachable endpoints and build direct tunnels, which is precisely what the design requires.

  • ✗

    Enable IPsec aggregate interfaces and set net-device disable on all tunnel interfaces.

    Why it's wrong here

    Aggregate IPsec interfaces bundle multiple tunnels into one logical interface for bandwidth, but they do not perform shortcut negotiation between spokes. Disabling net-device changes how tunnel interface addressing is handled and does not provide the NAT traversal or shortcut signalling needed. This combination would leave spoke-to-spoke traffic hairpinning through the hub rather than forming direct shortcuts as intended.

  • ✗

    Enable exchange-interface-ip and set mode-cfg on the spokes while disabling DPD on the hub.

    Why it's wrong here

    Exchange-interface-ip and mode-cfg affect interface addressing and IKE configuration payload handling, but they are not the mechanism that negotiates shortcuts between spokes. Disabling DPD on the hub would actually harm failure detection and shortcut maintenance. This set of changes does not provide the auto-discovery signalling or NAT traversal required for direct spoke-to-spoke tunnels.

  • ✗

    Set the hub as a dial-up server and configure the spokes with static VIP addresses on the NAT devices.

    Why it's wrong here

    Requiring static VIPs on the NAT devices contradicts the scenario, where spokes have dynamic public addresses and cannot publish a fixed endpoint. Dial-up server configuration on the hub is normal for ADVPN, but it does not by itself create spoke-to-spoke shortcuts. This approach would not scale to many NATed spokes and would not enable direct shortcut formation.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.