Courseiva
Troubleshoot →easyMultiple Select

PCNSE Troubleshoot Practice Question

Which TWO commands can be used to check the status of an IPSec tunnel on a Palo Alto Networks firewall?

⚠ Common exam trap

Watch out — candidates often confuse general network commands (like routing or interface status) with VPN-specific commands, assuming that a working route or interface implies a functional IPSec tunnel, when in fact the tunnel may be down due to IKE or IPSec SA failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

show vpn ike-sa

Option B, 'show vpn ike-sa', is correct because it displays the status of IKE Phase 1 security associations, which are the foundation of an IPSec tunnel and must be established before Phase 2 can come up. Option D, 'show vpn ipsec-sa', is correct because it shows the IPSec Phase 2 security associations, directly confirming whether the tunnel itself is active and passing traffic. Together these two commands let an administrator verify both phases of an IPSec VPN on a Palo Alto Networks firewall. Option A, 'show system info', only reports general device information such as model, software version, and uptime, not tunnel state. Option C, 'show routing route', displays the routing table and cannot show IKE or IPSec SA status. Option E, 'show interface all', shows interface statistics and link state, which is unrelated to IPSec tunnel status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    show system info

    Why it's wrong here

    'show system info' reports software version, hostname and uptime, exposing nothing about IPSec tunnel state. It tempts because it is a legitimate operational-status command, and it would be the correct choice when verifying firewall platform details before troubleshooting, but tunnel status requires IKE or IPSec-specific commands.

  • ✓

    show vpn ike-sa

    Why this is correct

    The show vpn ike-sa command displays Phase-1 IKE security associations, including peer addresses, state, and remaining lifetime. Inspecting it confirms whether the IKE tunnel itself is established, which is the required status check for an IPSec tunnel.

  • ✗

    show routing route

    Why it's wrong here

    The routing table shows path selection for traffic, not IPsec security association state, so it cannot confirm whether a tunnel is up. It would be correct for diagnosing forwarding or next-hop issues, whereas tunnel status requires commands querying IKE and IPsec SAs.

  • ✓

    show vpn ipsec-sa

    Why this is correct

    `show vpn ipsec-sa` lists active IPSec security associations, displaying tunnel names, peer addresses, and SPI values, which directly confirms whether a tunnel is established. It satisfies the stem's requirement to check IPSec tunnel status on a Palo Alto Networks firewall, complementing `show vpn ike-sa` for phase-1 verification.

  • ✗

    show interface all

    Why it's wrong here

    Displays interface counters and link state, which shows whether the physical or tunnel interface is up, but not IKE phase status or tunnel encryption. It is tempting because tunnel interfaces appear here, yet it cannot confirm an IPSec SA is established.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.