Fortinet
FCSS_NST_SE-7.6 · Question #88
Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?
The correct answer is B. Phase 2 is down. The key indicator is that child_num=0 (and sa=0 under the proxyid section), which means no IPsec child SAs (Phase 2 tunnels) are active - even though Phase 1 has been established, there are no Phase 2 SAs negotiated.
Resolve IPsec VPN Issues
Question
Refer to the exhibit, which contains the output of the command diagnose vpn tunnel list. What is the status of the tunnel?
Exhibit
Options
- ABoth Phase 1 and Phase 2 were negotiated successfully.
- BPhase 2 is down.
- CTraffic is passing through the tunnel.
- DPhase 1 is down.
How the community answered
(33 responses)- A15% (5)
- B76% (25)
- C6% (2)
- D3% (1)
Explanation
The key indicator is that child_num=0 (and sa=0 under the proxyid section), which means no IPsec child SAs (Phase 2 tunnels) are active - even though Phase 1 has been established, there are no Phase 2 SAs negotiated.
Topics
#IPsec VPN#Phase 2#tunnel status#diagnose vpn tunnel list
Community Discussion
No community discussion yet for this question.
