Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureHard

A network engineer is configuring a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party device. The third-party device requires the use of IKEv2 with AES256-GCM for encryption and SHA384 for authentication in Phase 2. Which IKE Crypto Profile and IPsec Crypto Profile settings are required?

  1. AIKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, DH Group 14.
  2. BIKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, DH Group 14 (PFS).
  3. CIKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, No PFS.
  4. DIKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, DH Group 16 (PFS).
Show answer & explanation

Correct answer: B. IKE Crypto Profile: DH Group 14, AES256, SHA256. IPsec Crypto Profile: AES256-GCM, SHA384, DH Group 14 (PFS).

The question specifies AES256-GCM for encryption and SHA384 for authentication in Phase 2, which corresponds to the IPsec Crypto Profile. GCM modes inherently include authentication, so SHA384 is redundant but must be configured if the peer requires it. The IKE Crypto Profile typically uses algorithms for key exchange (DH Group), encryption (AES), and authentication (SHA) for Phase 1. For Phase 2, if PFS (Perfect Forward Secrecy) is required, a DH Group must be selected; otherwise, 'No PFS' is used. The IKE Crypto Profile is usually configured with 256-bit encryption and SHA256 for integrity, and matching the DH Group (e.g., 14) from the IPsec profile or a stronger one (e.g., 14 or higher) is common. The key is matching the Phase 2 requirements for AES256-GCM and SHA384, and the inclusion of a DH Group for PFS in the IPsec Crypto Profile.

Why the other options are wrong

  • A. Does not explicitly mention PFS (DH Group 14) for IPsec, which is critical for Phase 2 security.
  • C. States 'No PFS', which contradicts the strong security requirements implied by AES256-GCM and SHA384.
  • D. Uses DH Group 16 for IPsec, while the IKE Crypto Profile uses DH Group 14. While possible, it's best practice to start with matching DH groups or ensure compatibility. The question doesn't state DH Group 16 is required.

IKE/IPsec Crypto Profiles

IKE and IPsec Crypto Profiles define the cryptographic algorithms and parameters used for establishing and securing VPN tunnels in Phase 1 (IKE) and Phase 2 (IPsec) respectively.

  • IKE Profile: Defines Phase 1 (key exchange, authentication, encryption, DH group).
  • IPsec Profile: Defines Phase 2 (data encryption, authentication, PFS DH group).
  • Parameters must match between peers for tunnel establishment.

Memory trick: IKE is the 'Key Exchange Initiator', IPsec is the 'Secure Data Tunnel'.

More Deploy and Configure questions