Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium

A network engineer is configuring a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party VPN device. The engineer needs to define the encryption, authentication, and Diffie-Hellman group for both IKE Phase 1 and IKE Phase 2. Which configuration objects are used for this purpose?

  1. AIKE Crypto Profile and IPsec Crypto Profile
  2. BIKE Gateway and IPsec Tunnel
  3. CGlobalProtect Gateway and GlobalProtect Portal
  4. DTunnel Interface and Security Policy
Show answer & explanation

Correct answer: A. IKE Crypto Profile and IPsec Crypto Profile

IKE Crypto Profiles define the Phase 1 parameters (encryption, authentication, DH group, lifetime), while IPsec Crypto Profiles define the Phase 2 parameters (encryption, authentication, DH group, lifetime, protocol). These are then referenced by the IKE Gateway and IPsec Tunnel configurations respectively.

Why the other options are wrong

  • B. IKE Gateway and IPsec Tunnel are the main objects that use the crypto profiles, but don't define the crypto parameters themselves.
  • C. GlobalProtect components are for remote access VPN, not site-to-site VPN crypto parameters.
  • D. Tunnel Interface is the logical interface for VPN traffic; Security Policy controls traffic through the tunnel, neither define crypto parameters.

IKE/IPsec Crypto Profiles

Configuration objects that define the cryptographic parameters (encryption, authentication, Diffie-Hellman group, and lifetime) for IKE Phase 1 (IKE Crypto Profile) and IKE Phase 2 (IPsec Crypto Profile) of a VPN tunnel.

  • IKE Crypto Profile: Defines Phase 1 security associations (SA).
  • IPsec Crypto Profile: Defines Phase 2 security associations (SA).
  • Ensures secure key exchange and data encryption for VPNs.
  • Must match on both ends of the VPN tunnel for successful establishment.

Memory trick: Crypto Profiles for phases of secure tunnels.

More Deploy and Configure questions