Courseiva

NSE7 Advanced VPN and Zero Trust Practice Question

An administrator is troubleshooting an OSPF over IPsec VPN overlay. The OSPF neighbor state is stuck in EXSTART. The VPN tunnel is up. Which TWO issues could cause this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP fragmentation issue due to GRE/IPsec overhead

Options A and E are correct because EXSTART is the stage where OSPF routers exchange DBD packets to elect Master/Slave, and these packets are large enough to exceed the reduced MTU caused by GRE/IPsec overhead. An IP fragmentation issue due to GRE/IPsec overhead (A) prevents the large DBD packets from being delivered or reassembled, so the routers keep retransmitting DBDs and never advance past EXSTART. An MTU mismatch on the tunnel interface (E) similarly causes large DBD packets to be dropped (or black-holed when DF is set), producing the same stuck-in-EXSTART symptom. Options B, C, and D are incorrect because a hello/dead interval mismatch (B) or an area ID mismatch (C) prevents the routers from forming a neighbor relationship at all, leaving them in DOWN or INIT, not EXSTART, and an IPsec phase2 proposal mismatch (D) would prevent the VPN tunnel from coming up, whereas the scenario states the tunnel is already up.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IP fragmentation issue due to GRE/IPsec overhead

    Why this is correct

    GRE/IPsec encapsulation adds overhead, so large OSPF hello or DBD packets can exceed the path MTU. If fragmentation is blocked, DBD packets carrying the master/slave election data never arrive intact, leaving neighbours stuck in EXSTART despite the tunnel being up.

  • ✗

    OSPF hello/dead interval mismatch

    Why it's wrong here

    Hello/dead interval mismatch causes hellos to be discarded, so neighbours never reach two-way state and remain in INIT or DOWN. Intervals are validated before database exchange, so this applies when adjacency fails to form rather than stalling at EXSTART.

  • ✗

    OSPF area ID mismatch

    Why it's wrong here

    Area ID mismatch prevents adjacency forming at all, leaving neighbours stuck in INIT or DOWN, not EXSTART. Area ID is checked during hello processing, so this would be the cause when routers never reach two-way communication.

  • ✗

    IPsec phase2 proposal mismatch

    Why it's wrong here

    A phase 2 proposal mismatch prevents the IPsec SA installing, so the tunnel would be down; the stem states it is up. Phase 2 parameters govern data encryption, whereas EXSTART stalls arise from MTU or MSS clamping problems.

  • ✓

    MTU mismatch on the tunnel interface

    Why this is correct

    An MTU mismatch on the tunnel interface causes OSPF DBD packets to be dropped during database exchange, preventing the neighbour relationship from progressing beyond EXSTART. The larger MTU side sends oversized DBD packets that the smaller MTU side discards, so the master/slave negotiation never completes despite the tunnel being up.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.