ExamGecko
Question list
Search
Search

Question 39 - NSE7_NST-7.2 discussion

Report
Export

Refer to the exhibit. which contains the output of diagnose vpn tunnel list.

Which command will capture ESP traffic for the VPN named DialUp_0?

A.
diagnose sniffer packet any 'host 10.0.10.10'
Answers
A.
diagnose sniffer packet any 'host 10.0.10.10'
B.
diagnose sniffer packet any 'ip proto 50'
Answers
B.
diagnose sniffer packet any 'ip proto 50'
C.
diagnose sniffer packet any 'esp and host 10*200.3.2'
Answers
C.
diagnose sniffer packet any 'esp and host 10*200.3.2'
D.
diagnose sniffer packet any 'port 4500'
Answers
D.
diagnose sniffer packet any 'port 4500'
Suggested answer: C

Explanation:

Capturing ESP Traffic:

ESP (Encapsulating Security Payload) traffic is associated with IPsec and is identified by the protocol number 50. To capture ESP traffic, you need to filter packets based on this protocol.

In this specific case, you also need to filter for the host associated with the VPN tunnel, which is 10.200.3.2 as indicated in the exhibit.

Sniffer Command:

The correct command to capture ESP traffic for the VPN named DialUp_0 is:

diagnose sniffer packet any 'esp and host 10.200.3.2'

This command ensures that only ESP packets to and from the specified host are captured, providing a focused and relevant data set for troubleshooting.

Fortinet Documentation: Verifying IPsec VPN Tunnels (Fortinet Docs) (Welcome to the Fortinet Community!).

Fortinet Community: Troubleshooting IPsec VPN Tunnels (Welcome to the Fortinet Community!) (Fortinet Docs).

asked 18/09/2024
Bonnie Lau
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first