nerdexam
Palo_Alto_Networks

PCNSE · Question #599

A security engineer received multiple reports of an IPSec VPN tunnel going down the night before. The engineer couldn't find any events related to VPN under system logs. What is the likely cause?

The correct answer is C. The Tunnel Monitor is not configured. This means that the firewall does not have a mechanism to monitor the status of the IPSec VPN tunnel and generate logs when it goes down or up. The Tunnel Monitor is an optional feature that can be enabled on each IPSec tunnel interface and it uses ICMP probes to check the…

Submitted by priya_blr· Apr 18, 2026Configuration Troubleshooting

Question

A security engineer received multiple reports of an IPSec VPN tunnel going down the night before. The engineer couldn't find any events related to VPN under system logs. What is the likely cause?

Options

  • ATunnel Inspection settings are misconfigured.
  • BThe log quota for GTP and Tunnel needs to be adjusted.
  • CThe Tunnel Monitor is not configured.
  • DDead Peer Detection is not enabled.

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    4% (1)
  • C
    80% (20)
  • D
    4% (1)

Explanation

This means that the firewall does not have a mechanism to monitor the status of the IPSec VPN tunnel and generate logs when it goes down or up. The Tunnel Monitor is an optional feature that can be enabled on each IPSec tunnel interface and it uses ICMP probes to check the connectivity of the tunnel peer. If the firewall does not receive a response from the peer after a specified number of retries, it marks the tunnel as down and logs an event. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/vpns/site-to-site-vpn- concepts/tunnel-monitoring

Topics

#VPN Troubleshooting#IPSec VPN#Tunnel Monitoring#Logging

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice