exam questions

Exam NSE7_EFW-7.0 All Questions

View all questions & answers for the NSE7_EFW-7.0 exam

Exam NSE7_EFW-7.0 topic 1 question 46 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 46
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Refer to the exhibit, which contains the output of the diagnose vpn tunnel list.

Which command will capture ESP traffic for the VPN named DialUp_0?

  • A. diagnose sniffer packet any ‘esp and host 10.200.3.2’
  • B. diagnose sniffer packet any ‘ip proto 50’
  • C. diagnose sniffer packet any ‘host 10.0.10.10’
  • D. diagnose sniffer packet any ‘port 4500’
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
LiliRose
Highly Voted 1 year, 5 months ago
Answer: B If you need to capture IPsec traffic, remember that the IP protocol and UDP port numbers depend on NAT-T and the use of NAT. If there is NO FG located in the middle that is running NAT, IKE traffic uses "UDP Port 500" and ESP traffic uses "IP Protocol 50". - Sniffers - No NAT IKE Traffic #Diagnose sniffer packet <port> 'host <remote-gateway> and udp port 500' ESP Traffic #Diagnose sniffer packet any 'host <remote-gateway> and esp' If NAT-T is enabled, and there is a FG located in the middle that is running NAT, the sniffer command must use a different filter: 1- In this case, IKE traffic uses "UDP Port 500", but switches to "UDP Port 4500" during the tunnel negotiation. 2- Additionally, ESP traffic is encapsulated inside the UDP 4500 channel. - Sniffer - NAT and NAT-T #Diagnose sniffer packet any 'host <remote-gateway> and (udp port 500 or udp port 4500)'
upvoted 7 times
racdab
1 year, 5 months ago
ESP = NAT-and NAT-T = Encapsulation in udp port 4500 ESP =NO NAT = uses "IP Protocol 50
upvoted 2 times
racdab
1 year, 5 months ago
nat is used so correct answer is D
upvoted 3 times
...
...
LiliRose
1 year, 5 months ago
Actually correct answer is D natt: silent
upvoted 2 times
...
...
J_Olin
Most Recent 2 months ago
Selected Answer: D
Because 'natt: mode=silent' the FortiGate, per RFC 3947, will use the UDP protocol on port 4500. This is why the sniffer should only be looking at port 4500. Hence, answer D.
upvoted 1 times
...
ay_dos
7 months, 2 weeks ago
Correct Answer A Unfortunately many see the Port4500 as meaning NAT is used. but unfortunately this is not the case. The VPN server will always listen on IKE port 500 and 4500, if port 500 fails it tries 4500 with or without NATT. If NATT is use bot server and clients uses the port 4500, but in this case 4500 is only used on one side. Note the IKE port is configurable. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-custom-IKE-port-between-two-FortiGate/ta-p/202107
upvoted 1 times
Yaserdfg
6 months, 2 weeks ago
NAT-T is forced , Natt mode silent https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPSec-VPN-nattraversal/ta-p/197873
upvoted 1 times
...
...
Georgezhong
11 months, 3 weeks ago
study guide pg.443
upvoted 2 times
...
Georgezhong
11 months, 3 weeks ago
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Different-methods-to-capture-packets-for-IPsec-VPN/ta-p/209471
upvoted 1 times
...
certifi46
1 year, 2 months ago
Selected Answer: D
nat t enabled
upvoted 1 times
...
wengzaii96
1 year, 2 months ago
which line show that NAT is in use?
upvoted 1 times
mau_80
1 year ago
port 4500
upvoted 1 times
Yaserdfg
6 months, 2 weeks ago
also mode is silent which means forced https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPSec-VPN-nattraversal/ta-p/197873
upvoted 1 times
...
...
...
Seph1
1 year, 3 months ago
Selected Answer: D
D - is correct Nat is used
upvoted 2 times
...
kocalin
1 year, 5 months ago
Selected Answer: D
natt is used, so correct answer is D. (NAT-T used UDP port 4500)
upvoted 3 times
...
jjejje
1 year, 6 months ago
Selected Answer: D
D answer
upvoted 2 times
...
jjejje
1 year, 6 months ago
D answer
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago