Courseiva
Authentication and VPN →mediumMultiple Select

NSE4 Authentication and VPN Practice Question

An administrator is troubleshooting an IPsec VPN that is not passing traffic. The Phase 1 and Phase 2 are both up. Which TWO CLI commands can be used to verify the VPN tunnel status and traffic flow? (Choose two.)

⚠ Common exam trap

Watch out — candidates often assume 'diagnose vpn ike config' (Option C) shows tunnel status because it relates to IKE, but it only displays static configuration, not the dynamic operational state or traffic counters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose vpn tunnel list

'diagnose vpn tunnel list' displays the status of all IPsec VPN tunnels, including Phase 1 and Phase 2 security associations (SAs), their uptime, and the number of packets transmitted and received. This allows the administrator to verify that the tunnel is established and to check for any packet drops or errors that might indicate a traffic flow issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    diagnose vpn tunnel list

    Why this is correct

    diagnose vpn tunnel list is the primary command for checking the live operational state of IPsec tunnels, showing phase 1 and phase 2 status, SPI values, and negotiation successes or failures. It clearly indicates whether the tunnel is established or down, making it the first step when a VPN connection is not working.

  • ✗

    execute ping-options source

    Why it's wrong here

    execute ping-options source configures the source IP address for ping packets, which is a testing parameter rather than a VPN diagnostic tool. While it might be used to test reachability through a specific interface or tunnel, it provides no information about IKE phase status, SA lifetimes, or tunnel negotiation errors.

  • ✗

    diagnose vpn ike config

    Why it's wrong here

    diagnose vpn ike config displays the static IKE configuration parameters such as encryption algorithms, hash methods, DH groups, and key lifetimes. This command does not show the current operational state of the tunnel or any dynamic session information, so it cannot reveal why a tunnel is down or encountering negotiation issues.

  • ✗

    diagnose netlink interface list

    Why it's wrong here

    diagnose netlink interface list outputs kernel-level network interface attributes like flags, MAC addresses, and IP bindings, which are not specific to IPSec VPN tunnels. It is useful for checking the underlay network but does not expose the IPSec SA table, tunnel up/down state, or any VPN protocol details, making it insufficient for tunnel troubleshooting.

  • ✓

    diagnose sys session list

    Why this is correct

    diagnose sys session list shows the active session table, and when filtered, it can reveal whether traffic is being forwarded through a VPN tunnel and how it is being processed. This command is valuable for confirming that traffic is actually traversing an established tunnel, but it does not directly check tunnel status; it is a secondary verification after confirming the tunnel is up.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.