Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The administrator notices that the VPN tunnel is up, but traffic is not passing through it. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is up with the correct selectors. Which command should the administrator use next to verify whether traffic is being encrypted and sent out?

⚠ Common exam trap

The trap here is assuming that because the tunnel is up, traffic must be encrypted, but it could be dropped by policy or routing before encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sniffer packet any 'host <remote_peer_ip> and esp' 4

When an IPsec tunnel is up but traffic is not passing, it is essential to verify whether packets are being encrypted and sent. The sniffer command with an ESP filter captures encrypted packets, confirming if encryption is occurring. If no ESP packets are seen, the issue may be with routing, firewall policies, or encryption domains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    diagnose firewall iprope list 100004

    Why it's wrong here

    The 'diagnose firewall iprope list 100004' command lists the firewall policy entries in the IP rope, which can help verify if the policy allows the traffic. But it does not show whether traffic is being encrypted and sent out; it only shows policy configuration.

  • ✗

    diagnose ip router lookup <remote_subnet>

    Why it's wrong here

    The 'diagnose ip router lookup' command shows the routing table lookup for a destination, which can help verify if the remote subnet is routed correctly. However, it does not show whether traffic is being encrypted and sent out; it only shows the next-hop interface and gateway.

  • ✓

    diagnose sniffer packet any 'host <remote_peer_ip> and esp' 4

    Why this is correct

    This command captures ESP packets between the local and remote peer, showing whether traffic is being encrypted and sent. If no ESP packets are seen, the issue may be with routing, firewall policies, or encryption. This directly verifies if traffic is being encrypted and transmitted.

  • ✗

    diagnose vpn ike log filter name <tunnel_name>

    Why it's wrong here

    The 'diagnose vpn ike log filter' command is used to filter IKE debug logs, which are for troubleshooting IKE phase 1 and phase 2 negotiations, not for verifying encrypted traffic. Since the tunnel is up, IKE is likely fine, and this command would not show whether traffic is being encrypted.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.