PCNSE Troubleshoot Practice Question
Which TWO commands can be used to check the status of an IPSec tunnel on a Palo Alto Networks firewall?
⚠ Common exam trap
Watch out — candidates often confuse general network commands (like routing or interface status) with VPN-specific commands, assuming that a working route or interface implies a functional IPSec tunnel, when in fact the tunnel may be down due to IKE or IPSec SA failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
show vpn ike-sa
Option B, 'show vpn ike-sa', is correct because it displays the status of IKE Phase 1 security associations, which are the foundation of an IPSec tunnel and must be established before Phase 2 can come up. Option D, 'show vpn ipsec-sa', is correct because it shows the IPSec Phase 2 security associations, directly confirming whether the tunnel itself is active and passing traffic. Together these two commands let an administrator verify both phases of an IPSec VPN on a Palo Alto Networks firewall. Option A, 'show system info', only reports general device information such as model, software version, and uptime, not tunnel state. Option C, 'show routing route', displays the routing table and cannot show IKE or IPSec SA status. Option E, 'show interface all', shows interface statistics and link state, which is unrelated to IPSec tunnel status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
show system info
Why it's wrong here
'show system info' reports software version, hostname and uptime, exposing nothing about IPSec tunnel state. It tempts because it is a legitimate operational-status command, and it would be the correct choice when verifying firewall platform details before troubleshooting, but tunnel status requires IKE or IPSec-specific commands.
- ✓
show vpn ike-sa
Why this is correct
The show vpn ike-sa command displays Phase-1 IKE security associations, including peer addresses, state, and remaining lifetime. Inspecting it confirms whether the IKE tunnel itself is established, which is the required status check for an IPSec tunnel.
- ✗
show routing route
Why it's wrong here
The routing table shows path selection for traffic, not IPsec security association state, so it cannot confirm whether a tunnel is up. It would be correct for diagnosing forwarding or next-hop issues, whereas tunnel status requires commands querying IKE and IPsec SAs.
- ✓
show vpn ipsec-sa
Why this is correct
`show vpn ipsec-sa` lists active IPSec security associations, displaying tunnel names, peer addresses, and SPI values, which directly confirms whether a tunnel is established. It satisfies the stem's requirement to check IPSec tunnel status on a Palo Alto Networks firewall, complementing `show vpn ike-sa` for phase-1 verification.
- ✗
show interface all
Why it's wrong here
Displays interface counters and link state, which shows whether the physical or tunnel interface is up, but not IKE phase status or tunnel encryption. It is tempting because tunnel interfaces appear here, yet it cannot confirm an IPSec SA is established.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.