Refer to the exhibit, which contains a screenshot of some phase 1 settings.

The VPN is up. To monitor traffic flow, the administrator enters the following CLI commands on an SSH session on FortiGate:
diagnose sniffer packet any 'udp and port 500' 4
diagnose debug enable
However, the sniffer does not show any output. Why?
Correct Answer: D
With NAT-T on, IKE traffic is encapsulated in UDP port 4500 (not port 500) once the tunnel is up, so your udp port 500filter never matches any packets.