NSE7 Advanced VPN and Zero Trust Practice Question
An administrator runs 'diagnose vpn ike gateway list' and sees that the IKE SA state is 'UP' but the IPsec SA state is 'DOWN'. The remote peer is a FortiGate. What is the most likely cause of this issue?
⚠ Common exam trap
NSE7 often tests the ability to distinguish Phase 1 from Phase 2 failures — candidates who see 'DOWN' and blame the pre-shared key miss that an UP IKE SA already proves Phase 1 succeeded.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Phase2 parameters (encryption, authentication, proxy IDs) do not match between the peers
When the IKE SA is UP but the IPsec SA is DOWN, Phase 1 (IKE) has succeeded but Phase 2 (IPsec) negotiation has failed. The most common cause is a mismatch in Phase 2 parameters — encryption/authentication algorithms, PFS settings, or proxy IDs (quick mode selectors) — between the two FortiGates. Since Phase 1 is up, the pre-shared key and basic reachability are already proven correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pre-shared key is incorrect
Why it's wrong here
A mismatched pre-shared key fails Phase 1, so the IKE SA would never reach UP. It is tempting because PSK errors are the most common VPN misconfiguration, but the stem shows IKE established, meaning Phase 2 parameters such as proxy IDs or encryption proposals are the likely fault.
- ✗
The tunnel interface is down
Why it's wrong here
A down tunnel interface would prevent IPsec traffic from being routed, but the IKE SA state being 'UP' confirms that IKE phase 1 completed successfully, which requires the tunnel interface to be administratively up and reachable. The IPsec SA state 'DOWN' indicates a failure in phase 2 negotiation, typically due to mismatched proxy IDs or traffic selectors. This option is tempting because a down tunnel interface is a common cause of total VPN failure, but here the IKE SA's 'UP' state rules out that interface-level issue.
- ✓
The Phase2 parameters (encryption, authentication, proxy IDs) do not match between the peers
Why this is correct
Phase 1 negotiates the IKE SA, which is UP, so peer identity and IKE proposals already match. Phase 2 builds the IPsec SA separately, so a DOWN IPsec SA with an UP IKE SA points to mismatched Phase 2 encryption, authentication, or proxy IDs between the peers.
- ✗
The firewall policy on the remote FortiGate is blocking UDP 500
Why it's wrong here
UDP 500 carries IKE negotiation, so blocking it would prevent the IKE SA from reaching UP; the stem already shows IKE established. It is tempting because UDP 500 is the classic IKE port to check, but here the failure sits in Phase 2, such as a proxy-ID or selector mismatch.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.