NSE7_EFW-6.4 Exam Question 56

An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled the IKE real time debug:
diagnose debug application ike-1
diagnose debug enable
In which order is each step and phase displayed in the debug output each time a new dial-up user is connecting to the VPN?
  • NSE7_EFW-6.4 Exam Question 57

    Refer to the exhibit, which shows a FortiGate configuration.

    An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however, the web filter is not inspecting any traffic that is passing through the policy.
    What must the administrator change to fix the issue?
  • NSE7_EFW-6.4 Exam Question 58

    Examine the IPsec configuration shown in the exhibit; then answer the question below.

    An administrator wants to monitor the VPN by enabling theIKE real time debug using these commands:
    diagnose vpn ike log-filter src-addr4 10.0.10.1
    diagnose debug application ike -1
    diagnose debug enable
    The VPN is currently up, there is no traffic crossing the tunnel and DPD packets are beinginterchanged between both IPsec gateways. However, the IKE real time debug does NOT show any output. Why isn't there any output?
  • NSE7_EFW-6.4 Exam Question 59

    In which two states is a given session categorized as ephemeral? (Choose two.)
  • NSE7_EFW-6.4 Exam Question 60

    Examine the output of the 'diagnose ips anomaly list' command shown in the exhibit; then answer the question below.

    Which IP addresses are included in the output of this command?