nerdexam
Fortinet

FCSS_NST_SE-7.6 · Question #88

Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?

The correct answer is B. Phase 2 is down. The key indicator is that child_num=0 (and sa=0 under the proxyid section), which means no IPsec child SAs (Phase 2 tunnels) are active - even though Phase 1 has been established, there are no Phase 2 SAs negotiated.

Resolve IPsec VPN Issues

Question

Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?

Exhibit

FCSS_NST_SE-7.6 question #88 exhibit

Options

  • ABoth Phase 1 and Phase 2 were negotiated successfully.
  • BPhase 2 is down.
  • CTraffic is passing through the tunnel.
  • DPhase 1 is down.

How the community answered

(33 responses)
  • A
    15% (5)
  • B
    76% (25)
  • C
    6% (2)
  • D
    3% (1)

Explanation

The key indicator is that child_num=0 (and sa=0 under the proxyid section), which means no IPsec child SAs (Phase 2 tunnels) are active - even though Phase 1 has been established, there are no Phase 2 SAs negotiated.

Topics

#IPsec VPN#Phase 2#tunnel status#diagnose vpn tunnel list

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.6 Practice