Courseiva
Secure Access and VPNmediumMultiple SelectObjective-mapped

PCNSE Secure Access and VPN Practice Question

Which THREE troubleshooting steps should be taken when a site-to-site VPN tunnel is up but no traffic passes?

⚠ Common exam trap

It's easy for candidates to assume a tunnel being 'up' guarantees traffic flow, but the PCNSE exam tests that you must separately verify routing, security policies, and proxy IDs—each of which can block traffic independently of the tunnel's control-plane state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify the routing table on both firewalls.

Even if the VPN tunnel is up (Phase 1 and Phase 2 SAs established), traffic may still fail if the firewall does not have a route to the destination network via the tunnel interface. Without a correct route in the routing table, the firewall will drop the packet or send it out the wrong interface. Verifying the routing table ensures that the tunnel interface is the next hop for the remote subnet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify the routing table on both firewalls.

    Why this is correct

    Correct. Routing must direct traffic into the tunnel.

  • Check the firewall policies for the tunnel zone.

    Why this is correct

    Correct. Security policies must allow traffic through the tunnel interface.

  • Increase the IPSec SA lifetime.

    Why it's wrong here

    Incorrect. Lifetime does not affect whether traffic passes; it controls renegotiation.

  • Verify the proxy IDs on both peers match.

    Why this is correct

    Correct. Mismatched proxy IDs prevent traffic from being encrypted.

  • Ensure the tunnel interface is placed in a virtual router.

    Why it's wrong here

    Incorrect. The tunnel interface is implicitly routed; placement is not required for basic connectivity.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 504 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.