Fortinet
FCSS_NST_SE-7.4 · Question #88
Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?
The correct answer is B. Phase 2 is down. The key indicator is that child_num=0 (and sa=0 under the proxyid section), which means no IPsec child SAs (Phase 2 tunnels) are active - even though Phase 1 has been established, there are no Phase 2 SAs negotiated.
VPN Troubleshooting
Question
Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?
Exhibit
Options
- ABoth Phase 1 and Phase 2 were negotiated successfully.
- BPhase 2 is down.
- CTraffic is passing through the tunnel.
- DPhase 1 is down.
How the community answered
(37 responses)- A8% (3)
- B73% (27)
- C3% (1)
- D16% (6)
Explanation
The key indicator is that child_num=0 (and sa=0 under the proxyid section), which means no IPsec child SAs (Phase 2 tunnels) are active - even though Phase 1 has been established, there are no Phase 2 SAs negotiated.
Topics
#IPsec#Phase 1#Phase 2#tunnel status
Community Discussion
No community discussion yet for this question.
