nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #45

Refer to the exhibit. An IPsec VPN tunnel is dropping, as shown by the debug output. Analyzing the debug output, what could be causing the tunnel to go down?

The correct answer is B. Dead Peer Detection is not receiving its acknowledge packet. The continual "notify msg received: R-U-THERE" without any corresponding DPD response causes the FortiGate to delete the IPsec SA when its Dead Peer Detection timer expires, bringing the tunnel down.

VPN Troubleshooting

Question

Refer to the exhibit. An IPsec VPN tunnel is dropping, as shown by the debug output. Analyzing the debug output, what could be causing the tunnel to go down?

Exhibit

FCSS_NST_SE-7.4 question #45 exhibit

Options

  • APhase 2 drops but Phase 1 is up.
  • BDead Peer Detection is not receiving its acknowledge packet.
  • CThe tunnel drops during rekey negotiation.
  • DThe tunnel drops after the timer expires.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    82% (23)
  • C
    4% (1)
  • D
    11% (3)

Explanation

The continual "notify msg received: R-U-THERE" without any corresponding DPD response causes the FortiGate to delete the IPsec SA when its Dead Peer Detection timer expires, bringing the tunnel down.

Topics

#IPsec VPN#Dead Peer Detection#DPD timeout#tunnel drop

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice