nerdexam
Fortinet

NSE4 · Question #39

Review the IPsec diagnostics output of the command diagnose vpn tunnel list shown in the exhibit. Which of the following statements is correct regarding this output? (Select one answer).

The correct answer is C. Two tunnels are up. Based on the diagnose vpn tunnel list output, if two tunnels are explicitly shown with an 'up' status, it means both IPsec tunnels are currently established and functional.

Submitted by noor.lb· Apr 18, 2026VPN and ZTNA

Question

Review the IPsec diagnostics output of the command diagnose vpn tunnel list shown in the exhibit. Which of the following statements is correct regarding this output? (Select one answer).

Exhibit

NSE4 question #39 exhibit

Options

  • AOne tunnel is rekeying.
  • BTwo tunnels are rekeying.
  • CTwo tunnels are up.
  • DOne tunnel is up.

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    10% (4)
  • C
    80% (33)
  • D
    7% (3)

Why each option

Based on the `diagnose vpn tunnel list` output, if two tunnels are explicitly shown with an 'up' status, it means both IPsec tunnels are currently established and functional.

AOne tunnel is rekeying.

If the output indicates two tunnels are 'up', stating only one is rekeying is incorrect, as rekeying is a transient state separate from a stable 'up' status.

BTwo tunnels are rekeying.

If the output indicates two tunnels are 'up', stating two are rekeying is incorrect, as rekeying implies an ongoing process rather than a fully established state.

CTwo tunnels are up.Correct

The `diagnose vpn tunnel list` command displays the current status of IPsec tunnels; if the output shows two tunnels explicitly in an 'up' state, it confirms that both Phase 1 and Phase 2 security associations are established for those tunnels.

DOne tunnel is up.

If the output explicitly shows two tunnels with an 'up' status, then stating only one tunnel is up is a direct contradiction of the diagnostic information.

Concept tested: FortiGate IPsec tunnel status interpretation

Source: https://docs.fortinet.com/document/fortigate/7.4.0/cli-reference/192250/vpn-ipsec

Topics

#IPsec VPN#VPN Diagnostics#FortiGate CLI#Tunnel Status

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice