Exam NSE7_SSE_AR-26 Topic 1 Question 17 Discussion
Actual exam question for Fortinet's NSE7_SSE_AR-26 exam
Question #: 17
Topic #: 1
Question #: 17
Topic #: 1
You configure the overlay tunnels for an SD-WAN hub-and-spoke topology defined with IPsec tunnels, BGP on loopback, and dynamic BGP. Which are two recommended IPsec settings for this topology? (Choose two.)
Suggested Answer: C,D Vote an answer
The hub should enable IKE mode configuration so it can dynamically assign tunnel IP addressing information to connecting spokes, which supports the dynamic overlay and routing design.
Each spoke should configure a local ID so the hub can uniquely identify the connecting spoke during IPsec negotiation, which is important when multiple dynamic spokes connect to the same hub.
Reference:
https://docs.fortinet.com/document/fortisase/7.4.0/spa-deployment-guide-using-bgp-per-overlay/347596/ipsec-vpn-configuration
https://docs.fortinet.com/document/overlay-as-a-service/24.4.0/sd-wan-overlay-migration-from-ocvpn-to-oaas-deployment-guide/497131/appendix-a-fortigate-configuration-settings-installed-by- oaas
Each spoke should configure a local ID so the hub can uniquely identify the connecting spoke during IPsec negotiation, which is important when multiple dynamic spokes connect to the same hub.
Reference:
https://docs.fortinet.com/document/fortisase/7.4.0/spa-deployment-guide-using-bgp-per-overlay/347596/ipsec-vpn-configuration
https://docs.fortinet.com/document/overlay-as-a-service/24.4.0/sd-wan-overlay-migration-from-ocvpn-to-oaas-deployment-guide/497131/appendix-a-fortigate-configuration-settings-installed-by- oaas
by Omar at Sep 10, 2026, 12:20 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).