nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #90

Refer to the exhibit, which contains a screenshot of some phase 1 settings. The VPN is up. To monitor traffic flow, the administrator enters the following CLI commands on an SSH session on…

The correct answer is D. NAT Traversal is enabled. With NAT-T on, IKE traffic is encapsulated in UDP port 4500 (not port 500) once the tunnel is up, so your udp port 500 filter never matches any packets.

VPN Troubleshooting

Question

Refer to the exhibit, which contains a screenshot of some phase 1 settings. The VPN is up. To monitor traffic flow, the administrator enters the following CLI commands on an SSH session on FortiGate:

diagnose sniffer packet any 'udp and port 500' 4 diagnose debug enable However, the sniffer does not show any output. Why?

Exhibit

FCSS_NST_SE-7.4 question #90 exhibit

Options

  • AChange the filter to sniff protocol TCP.
  • BIt must sniff IP address 10.0.10.1.
  • CChange the filter to sniff traffic on port1.
  • DNAT Traversal is enabled.

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    13% (4)
  • C
    3% (1)
  • D
    77% (23)

Explanation

With NAT-T on, IKE traffic is encapsulated in UDP port 4500 (not port 500) once the tunnel is up, so your udp port 500 filter never matches any packets.

Topics

#IKE#NAT traversal#port 4500#sniffer

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice