NSE7 Troubleshooting and Diagnostics Practice Question
A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is up with the correct selectors. Which command should the administrator use next to verify whether traffic is being encrypted and sent out?
⚠ Common exam trap
The trap here is assuming that because the tunnel is up, traffic must be encrypted, but it could be dropped by policy or routing before encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose sniffer packet any 'host <remote_peer_ip> and esp' 4
When an IPsec tunnel is up but traffic is not passing, it is essential to verify whether packets are being encrypted and sent. The sniffer command with an ESP filter captures encrypted packets, confirming if encryption is occurring. If no ESP packets are seen, the issue may be with routing, firewall policies, or encryption domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose firewall iprope list 100004
Why it's wrong here
The 'diagnose firewall iprope list 100004' command lists the firewall policy entries in the IP rope, which can help verify if the policy allows the traffic. But it does not show whether traffic is being encrypted and sent out; it only shows policy configuration.
- ✗
diagnose ip router lookup <remote_subnet>
Why it's wrong here
The 'diagnose ip router lookup' command shows the routing table lookup for a destination, which can help verify if the remote subnet is routed correctly. However, it does not show whether traffic is being encrypted and sent out; it only shows the next-hop interface and gateway.
- ✓
diagnose sniffer packet any 'host <remote_peer_ip> and esp' 4
Why this is correct
This command captures ESP packets between the local and remote peer, showing whether traffic is being encrypted and sent. If no ESP packets are seen, the issue may be with routing, firewall policies, or encryption. This directly verifies if traffic is being encrypted and transmitted.
- ✗
diagnose vpn ike log filter name <tunnel_name>
Why it's wrong here
The 'diagnose vpn ike log filter' command is used to filter IKE debug logs, which are for troubleshooting IKE phase 1 and phase 2 negotiations, not for verifying encrypted traffic. Since the tunnel is up, IKE is likely fine, and this command would not show whether traffic is being encrypted.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.