Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

A FortiGate is configured with a site-to-site IPsec VPN to a remote peer. The VPN tunnel is up, but traffic is not passing. The administrator runs 'diagnose vpn tunnel list' and sees that the tunnel is established with the correct selectors. Which two commands should the administrator use to further troubleshoot why traffic is not passing through the tunnel? (Choose two.)

⚠ Common exam trap

The trap here is focusing on IKE or tunnel status when the tunnel is already established; the problem is likely in routing or firewall policies affecting data traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose ip router lookup <destination_ip>

When an IPsec tunnel is up but traffic is not passing, the issue often lies in routing or firewall policies. Using 'diagnose debug flow filter' with the remote subnet allows the administrator to trace packet flow and see where packets are dropped. 'diagnose ip router lookup' verifies that the FortiGate routes traffic into the tunnel. Together, these commands help identify if traffic is being routed incorrectly or blocked by a policy, which are common causes for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    diagnose ip router lookup <destination_ip>

    Why this is correct

    This command performs a route lookup for a specific destination IP, showing which route and interface the FortiGate would use. If the route lookup shows the traffic is not being routed into the IPsec tunnel, that explains why traffic is not passing. In this scenario, checking the routing for a destination in the remote subnet can reveal if a more specific route is overriding the VPN route or if the tunnel interface is not in the routing table.

  • ✗

    diagnose vpn tunnel list

    Why it's wrong here

    The administrator already ran this command and saw that the tunnel is established with correct selectors. Running it again would not provide new information about why traffic is not passing. The next step should be to look at traffic flow and routing, not to re-check the tunnel status. Therefore, this command is not one of the two that should be used for further troubleshooting.

  • ✗

    diagnose firewall iprope list

    Why it's wrong here

    This command displays the IP rope configuration, which shows how traffic is matched to policies. While it can be useful for policy troubleshooting, it does not show real-time packet flow or routing decisions. In this scenario, the issue is likely with routing or policy drops, and the more direct commands are debug flow and route lookup. Therefore, this command is less helpful than the other two options.

  • ✗

    diagnose vpn ike log filter src-addr <remote_gateway>

    Why it's wrong here

    This command filters IKE debug logs for a specific source address. While useful for troubleshooting IKE negotiations, the tunnel is already established, so IKE debugging is not relevant. The issue is with data traffic not passing, not with tunnel establishment. Therefore, this command would not help identify why traffic is failing after the tunnel is up.

  • ✓

    diagnose debug flow filter addr <remote_subnet>

    Why this is correct

    This command sets a filter to capture debug flow output for traffic to or from the remote subnet. It helps trace the path of packets through the FortiGate, showing if they are being denied by a policy, routed incorrectly, or dropped. In this scenario, since the tunnel is up but traffic is not passing, using debug flow with a filter on the remote subnet will reveal where the packets are being dropped.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.