A Site-to-Site VPN tunnel from your main office to an Azure virtual network fails to establish. You need to inspect a diagnostic log that helps determine why the IPsec tunnel negotiation failed. Which diagnostic log should you review?
Choose an answer
Tap an option to check your answer.
Correct answer: IKEDiagnosticLog.
Why this is the answer
The IKEDiagnosticLog provides detailed information about Internet Key Exchange (IKE) negotiations, which are crucial for establishing IPsec tunnels. When a Site-to-Site VPN tunnel fails to establish, issues often lie within the IKE phase (Phase 1 or Phase 2) of the IPsec negotiation, such as mismatched encryption algorithms, authentication failures, or incorrect pre-shared keys. Reviewing this log helps identify the specific negotiation step that failed. RouteDiagnosticLog focuses on routing issues, not IPsec tunnel establishment. GatewayDiagnosticLog offers general gateway health and activity but lacks the granular detail for IPsec negotiation failures. TunnelDiagnosticLog provides information about the tunnel's status once established, but not the negotiation process itself.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed