nerdexam
Palo_Alto_Networks

PCNSE · Question #831

After configuring an IPSec tunnel, how should a firewall administrator initiate the IKE phase 1 to see if it will come up?

The correct answer is D. test vpn ike-sa gateway <gateway_name>. To test if IKE Phase 1 is coming up after configuring an IPSec tunnel, the firewall administrator should use the command <gateway_name>. This command test vpn ike-sa gateway initiates the IKE Phase 1 negotiation with the specified gateway, allowing the administrator to check…

Submitted by omar99· Apr 18, 2026Operate

Question

After configuring an IPSec tunnel, how should a firewall administrator initiate the IKE phase 1 to see if it will come up?

Options

  • Adebug ike stat
  • Btest vpn ipsec-sa tunnel <tunnel_name>
  • Cshow vpn ipsec-sa tunnel <tunnel_name>
  • Dtest vpn ike-sa gateway <gateway_name>

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    4% (2)
  • D
    91% (43)

Explanation

To test if IKE Phase 1 is coming up after configuring an IPSec tunnel, the firewall administrator should use the command <gateway_name>. This command test vpn ike-sa gateway initiates the IKE Phase 1 negotiation with the specified gateway, allowing the administrator to check whether the tunnel establishes successfully.

Topics

#IPSec VPN#IKE Phase 1#CLI Commands#VPN Verification

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice