nerdexam
Fortinet

NSE7_EFW · Question #17

NSE7_EFW Question #17: Real Exam Question with Answer & Explanation

Sign in or unlock NSE7_EFW to reveal the answer and full explanation for question #17. The question stem and answer options stay visible for context.

Question

Examine the IPsec configuration shown in the exhibit; then answer the question below. An administrator wants to monitor the VPN by enable the IKE real time debug using these commands: diagnose vpn ike log-filter src-addr4 10.0.10.1 diagnose debug application ike -1 diagnose debug enable The VPN is currently up, there is no traffic crossing the tunnel and DPD packets are being interchanged between both Ipsec gateways. However, the IKE rea time debug does NOT show any output. Why isn't there any output?

Exhibit

NSE7_EFW question #17 exhibit

Options

  • AThe IKE real time debug shows the phases 1 and 2 negotiations only. It does not show any more
  • BThe log-filter setting is set incorrectly. The VPN's traffic does not match this filter.
  • CThe IKF real time debug shows the phase 1 negotiation only. For information after that, the
  • DThe IKE real time debug shows error messages only. If it does not provide any output, it indicates

Unlock NSE7_EFW to see the answer

You've previewed enough free NSE7_EFW questions. Unlock NSE7_EFW for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full NSE7_EFW Practice