Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE7_SSE_AD-25 Exam - Topic 1 Question 6 Discussion

Actual exam question for Fortinet's NSE7_SSE_AD-25 exam
Question #: 6
Topic #: 1
[All NSE7_SSE_AD-25 Questions]

How does FortiSASE Secure Private Access (SPA) facilitate connectivity to private resources in a hub-and-spoke network? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: D

FortiSASE Secure Private Access (SPA) is designed to provide remote users with seamless and secure access to private applications hosted behind an organization's FortiGate Next-Generation Firewall (NGFW) or SD-WAN hubs.2

Hub-and-Spoke Architecture: In this deployment model, the organization's FortiGate (either a standalone NGFW or an SD-WAN hub) acts as the hub, while the global FortiSASE Security Points of Presence (PoPs) act as spokes.3

IPsec and BGP Integration: The connectivity between the FortiSASE PoPs and the corporate hub is established via IPsec VPN tunnels. To manage routing and ensure that remote users can reach the correct internal subnets, Border Gateway Protocol (BGP) is used for dynamic route exchange.4 This allows the hub to advertise internal prefixes to FortiSASE, enabling the PoPs to route user traffic effectively without requiring complex static route management.

Simplified Configuration: To reduce administrative overhead and prevent manual configuration errors on the FortiOS side, Fortinet introduced the SPA easy configuration key (also known as an invitation code or simplified SPA setup). An administrator generates this key in the FortiSASE portal and enters it on the FortiGate hub. This triggers the Fabric Overlay Orchestrator to automatically provision the necessary IPsec tunnels, BGP peerings, and firewall policies required for SPA connectivity.

According to the FortiSASE 25 Architecture Guide, this method is preferred over legacy VPNs because it supports both TCP and UDP traffic, integrates natively with existing SD-WAN deployments, and automatically finds the shortest path to applications using ADVPN (Auto-Discovery VPN) shortcuts where applicable.


Contribute your Thoughts:

0/2000 characters
Dominga
3 days ago
I’m not sure about the whole "easy configuration key" thing. Is it really that simple?
upvoted 0 times
...
Fausto
9 days ago
Option A sounds interesting too, but I’m leaning towards D.
upvoted 0 times
...
Fredric
14 days ago
Wait, I thought SPA didn't use BGP? This is confusing.
upvoted 0 times
...
Reena
19 days ago
Totally agree with you, Oren! D makes the most sense here.
upvoted 0 times
...
Oren
24 days ago
I think option D is the right choice. IPsec and BGP are key for dynamic routing.
upvoted 0 times
...
Crista
29 days ago
I vaguely remember something about SNAT being involved, but I can't remember if that's specific to SPA or something else entirely.
upvoted 0 times
...
Lindsey
1 month ago
I feel like the answer might be D, since it mentions dynamic route exchange, which seems important for connectivity.
upvoted 0 times
...
Lashawn
1 month ago
I remember practicing a question about SPA and how it simplifies setup, but I can't recall if it was about direct links or using protocols.
upvoted 0 times
...
Julie
1 month ago
I think SPA uses IPsec and BGP for connecting to hubs, but I'm not sure if it's the only option.
upvoted 0 times
...

Save Cancel