NSE7 Troubleshooting and Diagnostics Practice Question
An administrator is troubleshooting an IPsec VPN tunnel that establishes phase 1 but fails phase 2. Which TWO commands are MOST useful to diagnose the phase 2 failure? (Choose two.)
⚠ Common exam trap
Many exam-takers choose 'show vpn ipsec phase2-interface' (B) thinking it shows real-time negotiation status, but it only displays static configuration, not the dynamic debug output needed to see why the peer rejects the proposal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
diagnose vpn ike config
The 'diagnose vpn ike config' command (D) displays the IKE configuration that the FortiGate is actually using for phase 2 negotiations, including proxy IDs, encryption algorithms, and lifetimes. This helps identify mismatches between the local and peer configurations that cause phase 2 to fail. The 'diagnose debug application ike 255' command (E) enables verbose IKE debugging, which logs every phase 2 exchange, including error messages like 'no proposal chosen' or 'mismatched proxy ID', directly pinpointing the failure reason.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
diagnose sys session list
Why it's wrong here
Lists sessions, not IKE negotiation details.
- ✗
show vpn ipsec phase2-interface
Why it's wrong here
Shows configuration, not real-time negotiation.
- ✗
get system performance status
Why it's wrong here
Shows overall performance, not IKE details.
- ✓
diagnose vpn ike config
Why this is correct
Shows phase 2 proposals and selectors.
- ✓
diagnose debug application ike 255
Why this is correct
Enables detailed IKE debug output.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.