nerdexam
Fortinet

FCSS_NST_SE-7.6 · Question #34

Refer to the exhibit, which contains a screenshot of some phase 1 settings. The VPN is not up. To diagnose the issue, the administrator enters the following CLI commands on an SSH session on…

The correct answer is A. The administrator must also run the command diagnose debug enable. You've hit your limit · resets 1pm (America/New_York)

Resolve IPsec VPN Issues

Question

Refer to the exhibit, which contains a screenshot of some phase 1 settings. The VPN is not up. To diagnose the issue, the administrator enters the following CLI commands on an SSH session on FortiGate:

However, the IKE real-time debug does not show any output. Why?

Exhibit

FCSS_NST_SE-7.6 question #34 exhibit

Options

  • AThe administrator must also run the command diagnose debug enable.
  • BThe debug shows only error messages. If there is no output, then the phase 1 and phase 2
  • CThe log-filter setting is incorrect. The VPN traffic does not match this filter.
  • DReplace diagnose debug application ike -1 with diagnose debug application ipsec -1.

How the community answered

(43 responses)
  • A
    74% (32)
  • B
    14% (6)
  • C
    5% (2)
  • D
    7% (3)

Explanation

You've hit your limit · resets 1pm (America/New_York)

Topics

#IKE real-time debug#diagnose debug enable#VPN troubleshooting#phase 1

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.6 Practice