A FortiGate administrator is troubleshooting an IPsec VPN tunnel that fails to establish. The administrator runs 'diagnose vpn ike gateway list' and sees the tunnel state as 'connecting' but no phase2 selectors are listed. Which step should the administrator take next to identify the issue?
When phase2 selectors are missing, it indicates that phase2 negotiation has not completed or failed. Enabling IKE debug with 'diagnose debug application ike -1' will show the detailed exchange, including proposals, selectors, and any error messages. This is the most effective way to identify why phase2 is not establishing, such as mismatched proposals or proxy IDs. The debug output will pinpoint the failure.
Why this answer
When an IPsec tunnel is stuck in 'connecting' with no phase2 selectors, the issue is likely in phase2 negotiation. Enabling IKE debug with 'diagnose debug application ike -1' will show the detailed negotiation, including proposals and selectors, and any error messages. This is the best next step to identify the cause, such as mismatched phase2 proposals or incorrect proxy IDs.
Other commands may not provide the necessary detail.
Exam trap
The trap here is using summary commands like 'diagnose vpn tunnel list' or incorrect commands instead of enabling detailed IKE debug to see the actual negotiation failure.