NSE7 Troubleshooting and Diagnostics Practice Question
A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The VPN tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. Which two commands should the administrator use to further troubleshoot why traffic is not passing through the tunnel? (Choose two.)
⚠ Common exam trap
The trap here is focusing on IKE or tunnel status when the tunnel is already established; the problem is likely in routing or firewall policies affecting data traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose ip router lookup <destination_ip>
When an IPsec tunnel is up but traffic is not passing, the issue often lies in routing or firewall policies. Using 'diagnose debug flow filter' with the remote subnet allows the administrator to trace packet flow and see where packets are dropped. 'diagnose ip router lookup' verifies that the FortiGate routes traffic into the tunnel. Together, these commands help identify if traffic is being routed incorrectly or blocked by a policy, which are common causes for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
diagnose ip router lookup <destination_ip>
Why this is correct
This command performs a route lookup for a specific destination IP, showing which route and interface the FortiGate would use. If the route lookup shows the traffic is not being routed into the IPsec tunnel, that explains why traffic is not passing. In this scenario, checking the routing for a destination in the remote subnet can reveal if a more specific route is overriding the VPN route or if the tunnel interface is not in the routing table.
- ✗
diagnose vpn tunnel list
Why it's wrong here
The administrator already ran this command and saw that the tunnel is established with correct selectors. Running it again would not provide new information about why traffic is not passing. The next step should be to look at traffic flow and routing, not to re-check the tunnel status. Therefore, this command is not one of the two that should be used for further troubleshooting.
- ✗
diagnose firewall iprope list
Why it's wrong here
This command displays the IP rope configuration, which shows how traffic is matched to policies. While it can be useful for policy troubleshooting, it does not show real-time packet flow or routing decisions. In this scenario, the issue is likely with routing or policy drops, and the more direct commands are debug flow and route lookup. Therefore, this command is less helpful than the other two options.
- ✗
diagnose vpn ike log filter src-addr <remote_gateway>
Why it's wrong here
This command filters IKE debug logs for a specific source address. While useful for troubleshooting IKE negotiations, the tunnel is already established, so IKE debugging is not relevant. The issue is with data traffic not passing, not with tunnel establishment. Therefore, this command would not help identify why traffic is failing after the tunnel is up.
- ✓
diagnose debug flow filter addr <remote_subnet>
Why this is correct
This command sets a filter to capture debug flow output for traffic to or from the remote subnet. It helps trace the path of packets through the FortiGate, showing if they are being denied by a policy, routed incorrectly, or dropped. In this scenario, since the tunnel is up but traffic is not passing, using debug flow with a filter on the remote subnet will reveal where the packets are being dropped.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.