NSE4 · Question #45
Review the IPsec diagnostics output of the command diagnose vpn tunnel list shown in the exhibit below. Which statements are correct regarding this output? (Choose two.)
The correct answer is A. The connecting client has been allocated address 172.20.1.1. B. In the Phase 1 settings, dead peer detection is enabled. The diagnose vpn tunnel list output confirms that a connecting VPN client has been allocated the IP address 172.20.1.1 and that Dead Peer Detection (DPD) is enabled in the Phase 1 settings for the tunnel.
Question
Review the IPsec diagnostics output of the command diagnose vpn tunnel list shown in the exhibit below. Which statements are correct regarding this output? (Choose two.)
Exhibit
Options
- AThe connecting client has been allocated address 172.20.1.1.
- BIn the Phase 1 settings, dead peer detection is enabled.
- CThe tunnel is idle.
- DThe connecting client has been allocated address 10.200.3.1.
How the community answered
(25 responses)- A80% (20)
- C8% (2)
- D12% (3)
Why each option
The `diagnose vpn tunnel list` output confirms that a connecting VPN client has been allocated the IP address 172.20.1.1 and that Dead Peer Detection (DPD) is enabled in the Phase 1 settings for the tunnel.
The `diagnose vpn tunnel list` command provides detailed information about active IPsec tunnels, including the internal IP address that has been dynamically assigned to a connected VPN client, which the output indicates as 172.20.1.1.
The diagnostics output includes the configuration parameters of the IPsec tunnel's Phase 1, explicitly showing whether Dead Peer Detection (DPD) is enabled (`dpd-link: enable`) to monitor the liveness and availability of the remote peer.
The `diagnose vpn tunnel list` command typically displays information for active or established tunnels; while a tunnel can be idle (no traffic), the primary purpose of this command is to list currently functioning VPN connections.
If the connecting client has been allocated 172.20.1.1 (as per choice A), it cannot also be simultaneously allocated 10.200.3.1 for the same VPN connection.
Concept tested: IPsec tunnel diagnostics interpretation (FortiGate)
Source: https://docs.fortinet.com/document/fortigate/7.4.0/cli-reference/263590/diagnose-vpn-tunnel
Topics
Community Discussion
No community discussion yet for this question.
