NSE7 Advanced VPN and Zero Trust Practice Question
An administrator is troubleshooting an OSPF over IPsec VPN overlay. The OSPF neighbor state is stuck in EXSTART. The VPN tunnel is up. Which TWO issues could cause this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP fragmentation issue due to GRE/IPsec overhead
Options A and E are correct because EXSTART is the stage where OSPF routers exchange DBD packets to elect Master/Slave, and these packets are large enough to exceed the reduced MTU caused by GRE/IPsec overhead. An IP fragmentation issue due to GRE/IPsec overhead (A) prevents the large DBD packets from being delivered or reassembled, so the routers keep retransmitting DBDs and never advance past EXSTART. An MTU mismatch on the tunnel interface (E) similarly causes large DBD packets to be dropped (or black-holed when DF is set), producing the same stuck-in-EXSTART symptom. Options B, C, and D are incorrect because a hello/dead interval mismatch (B) or an area ID mismatch (C) prevents the routers from forming a neighbor relationship at all, leaving them in DOWN or INIT, not EXSTART, and an IPsec phase2 proposal mismatch (D) would prevent the VPN tunnel from coming up, whereas the scenario states the tunnel is already up.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IP fragmentation issue due to GRE/IPsec overhead
Why this is correct
GRE/IPsec encapsulation adds overhead, so large OSPF hello or DBD packets can exceed the path MTU. If fragmentation is blocked, DBD packets carrying the master/slave election data never arrive intact, leaving neighbours stuck in EXSTART despite the tunnel being up.
- ✗
OSPF hello/dead interval mismatch
Why it's wrong here
Hello/dead interval mismatch causes hellos to be discarded, so neighbours never reach two-way state and remain in INIT or DOWN. Intervals are validated before database exchange, so this applies when adjacency fails to form rather than stalling at EXSTART.
- ✗
OSPF area ID mismatch
Why it's wrong here
Area ID mismatch prevents adjacency forming at all, leaving neighbours stuck in INIT or DOWN, not EXSTART. Area ID is checked during hello processing, so this would be the cause when routers never reach two-way communication.
- ✗
IPsec phase2 proposal mismatch
Why it's wrong here
A phase 2 proposal mismatch prevents the IPsec SA installing, so the tunnel would be down; the stem states it is up. Phase 2 parameters govern data encryption, whereas EXSTART stalls arise from MTU or MSS clamping problems.
- ✓
MTU mismatch on the tunnel interface
Why this is correct
An MTU mismatch on the tunnel interface causes OSPF DBD packets to be dropped during database exchange, preventing the neighbour relationship from progressing beyond EXSTART. The larger MTU side sends oversized DBD packets that the smaller MTU side discards, so the master/slave negotiation never completes despite the tunnel being up.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.