NSE4 · Question #39
Review the IPsec diagnostics output of the command diagnose vpn tunnel list shown in the exhibit. Which of the following statements is correct regarding this output? (Select one answer).
The correct answer is C. Two tunnels are up. Based on the diagnose vpn tunnel list output, if two tunnels are explicitly shown with an 'up' status, it means both IPsec tunnels are currently established and functional.
Question
Review the IPsec diagnostics output of the command diagnose vpn tunnel list shown in the exhibit. Which of the following statements is correct regarding this output? (Select one answer).
Exhibit
Options
- AOne tunnel is rekeying.
- BTwo tunnels are rekeying.
- CTwo tunnels are up.
- DOne tunnel is up.
How the community answered
(41 responses)- A2% (1)
- B10% (4)
- C80% (33)
- D7% (3)
Why each option
Based on the `diagnose vpn tunnel list` output, if two tunnels are explicitly shown with an 'up' status, it means both IPsec tunnels are currently established and functional.
If the output indicates two tunnels are 'up', stating only one is rekeying is incorrect, as rekeying is a transient state separate from a stable 'up' status.
If the output indicates two tunnels are 'up', stating two are rekeying is incorrect, as rekeying implies an ongoing process rather than a fully established state.
The `diagnose vpn tunnel list` command displays the current status of IPsec tunnels; if the output shows two tunnels explicitly in an 'up' state, it confirms that both Phase 1 and Phase 2 security associations are established for those tunnels.
If the output explicitly shows two tunnels with an 'up' status, then stating only one tunnel is up is a direct contradiction of the diagnostic information.
Concept tested: FortiGate IPsec tunnel status interpretation
Source: https://docs.fortinet.com/document/fortigate/7.4.0/cli-reference/192250/vpn-ipsec
Topics
Community Discussion
No community discussion yet for this question.
