NSE4 Authentication and VPN Practice Question
An administrator is troubleshooting an IPsec VPN that is not passing traffic. The Phase 1 and Phase 2 are both up. Which TWO CLI commands can be used to verify the VPN tunnel status and traffic flow? (Choose two.)
⚠ Common exam trap
Watch out — candidates often assume 'diagnose vpn ike config' (Option C) shows tunnel status because it relates to IKE, but it only displays static configuration, not the dynamic operational state or traffic counters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose vpn tunnel list
'diagnose vpn tunnel list' displays the status of all IPsec VPN tunnels, including Phase 1 and Phase 2 security associations (SAs), their uptime, and the number of packets transmitted and received. This allows the administrator to verify that the tunnel is established and to check for any packet drops or errors that might indicate a traffic flow issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
diagnose vpn tunnel list
Why this is correct
diagnose vpn tunnel list is the primary command for checking the live operational state of IPsec tunnels, showing phase 1 and phase 2 status, SPI values, and negotiation successes or failures. It clearly indicates whether the tunnel is established or down, making it the first step when a VPN connection is not working.
- ✗
execute ping-options source
Why it's wrong here
execute ping-options source configures the source IP address for ping packets, which is a testing parameter rather than a VPN diagnostic tool. While it might be used to test reachability through a specific interface or tunnel, it provides no information about IKE phase status, SA lifetimes, or tunnel negotiation errors.
- ✗
diagnose vpn ike config
Why it's wrong here
diagnose vpn ike config displays the static IKE configuration parameters such as encryption algorithms, hash methods, DH groups, and key lifetimes. This command does not show the current operational state of the tunnel or any dynamic session information, so it cannot reveal why a tunnel is down or encountering negotiation issues.
- ✗
diagnose netlink interface list
Why it's wrong here
diagnose netlink interface list outputs kernel-level network interface attributes like flags, MAC addresses, and IP bindings, which are not specific to IPSec VPN tunnels. It is useful for checking the underlay network but does not expose the IPSec SA table, tunnel up/down state, or any VPN protocol details, making it insufficient for tunnel troubleshooting.
- ✓
diagnose sys session list
Why this is correct
diagnose sys session list shows the active session table, and when filtered, it can reveal whether traffic is being forwarded through a VPN tunnel and how it is being processed. This command is valuable for confirming that traffic is actually traversing an established tunnel, but it does not directly check tunnel status; it is a secondary verification after confirming the tunnel is up.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.