A customer has an S2S VPN using a VpnGw1 gateway (gw-prod) and reports the tunnel is down. You need to run Azure Network Watcher diagnostics specific to VPN gateway and connection to rapidly identify root causes such as BGP status, IKE/IPSec negotiation failures, or gateway health. Which approach is most appropriate?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Network Watcher VPN diagnostics for the gateway/connection (run the VPN diagnostics check for the specific connection and gateway) to get diagnostic outputs about tunnel status, BGP sessions, and IKE/IPSec negotiation..
Why this is the answer
The most appropriate approach is to use Network Watcher VPN diagnostics for the gateway and connection. This feature is specifically designed to provide detailed diagnostic outputs for VPN tunnels, including tunnel status, BGP sessions, and IKE/IPSec negotiation failures, which directly addresses the reported issues. Running IP Flow Verify from a VM is useful for checking NSG rules but doesn't provide specific VPN tunnel diagnostics. Opening a packet capture on the VPN gateway is not directly supported for managed Azure VPN gateways in the same way it is for VM-based appliances. Deleting and redeploying the gateway is a drastic measure that would cause further downtime and should only be considered after thorough diagnostics.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed