Courseiva

NSE7 Troubleshooting and Diagnostics Practice Question

An administrator is troubleshooting a FortiGate that is experiencing intermittent packet loss for traffic passing through an IPsec VPN tunnel. The administrator wants to capture packets on the VPN interface to analyze the issue. Which command should the administrator use to capture packets on the IPsec tunnel interface named 'vpn1'?

⚠ Common exam trap

The trap here is capturing on the physical interface or 'any' and assuming it will show the tunneled traffic, when in fact the VPN interface must be specified to see the decrypted packets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

diagnose sniffer packet vpn1 'host 10.1.1.1' 4

To capture packets on a specific IPsec tunnel interface, the administrator should use 'diagnose sniffer packet <interface>' with the appropriate filter and verbosity. This allows capturing the decrypted traffic inside the tunnel, which is essential for analyzing packet loss. Capturing on the physical interface would only show encrypted packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    diagnose debug application ike -1

    Why it's wrong here

    This command enables IKE debug, which is useful for troubleshooting VPN negotiation issues, but it does not capture packet data. It provides information about IKE negotiations, not the actual traffic passing through the tunnel. For packet loss analysis, a sniffer capture is required.

  • ✗

    diagnose sniffer packet port1 'host 10.1.1.1' 4

    Why it's wrong here

    This command captures on the physical interface 'port1', which may be the underlying interface for the VPN, but it will capture encrypted packets, not the decrypted traffic inside the tunnel. To analyze the actual payload, capturing on the VPN interface is necessary. This would not provide the needed visibility.

  • ✓

    diagnose sniffer packet vpn1 'host 10.1.1.1' 4

    Why this is correct

    This command captures packets on the 'vpn1' interface with a filter for host 10.1.1.1 and verbosity level 4, which provides detailed packet information including interface names. This is the correct syntax to capture traffic on a specific IPsec tunnel interface for troubleshooting packet loss.

  • ✗

    diagnose sniffer packet any 'host 10.1.1.1' 4

    Why it's wrong here

    Capturing on 'any' interface will include all interfaces, which can generate excessive output and make it difficult to isolate traffic on the VPN tunnel. While it may capture the desired packets, it is not the most efficient or targeted approach. The administrator specifically wants to capture on the VPN interface.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 718 original NSE7 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.