nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #88

Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?

The correct answer is B. Phase 2 is down. The key indicator is that child_num=0 (and sa=0 under the proxyid section), which means no IPsec child SAs (Phase 2 tunnels) are active - even though Phase 1 has been established, there are no Phase 2 SAs negotiated.

VPN Troubleshooting

Question

Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?

Exhibit

FCSS_NST_SE-7.4 question #88 exhibit

Options

  • ABoth Phase 1 and Phase 2 were negotiated successfully.
  • BPhase 2 is down.
  • CTraffic is passing through the tunnel.
  • DPhase 1 is down.

How the community answered

(37 responses)
  • A
    8% (3)
  • B
    73% (27)
  • C
    3% (1)
  • D
    16% (6)

Explanation

The key indicator is that child_num=0 (and sa=0 under the proxyid section), which means no IPsec child SAs (Phase 2 tunnels) are active - even though Phase 1 has been established, there are no Phase 2 SAs negotiated.

Topics

#IPsec#Phase 1#Phase 2#tunnel status

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice