Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A network engineer is configuring a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party VPN device. The engineer needs to define the encryption, authentication, and Diffie-Hellman group for both IKE Phase 1 and IKE Phase 2. Which configuration objects are used for this purpose?
- AIKE Crypto Profile and IPsec Crypto Profile
- BIKE Gateway and IPsec Tunnel
- CGlobalProtect Gateway and GlobalProtect Portal
- DTunnel Interface and Security Policy
Show answer & explanationAnswer & explanation
Correct answer: A. IKE Crypto Profile and IPsec Crypto Profile
IKE Crypto Profiles define the Phase 1 parameters (encryption, authentication, DH group, lifetime), while IPsec Crypto Profiles define the Phase 2 parameters (encryption, authentication, DH group, lifetime, protocol). These are then referenced by the IKE Gateway and IPsec Tunnel configurations respectively.
Why the other options are wrong
- B. IKE Gateway and IPsec Tunnel are the main objects that use the crypto profiles, but don't define the crypto parameters themselves.
- C. GlobalProtect components are for remote access VPN, not site-to-site VPN crypto parameters.
- D. Tunnel Interface is the logical interface for VPN traffic; Security Policy controls traffic through the tunnel, neither define crypto parameters.
IKE/IPsec Crypto Profiles
Configuration objects that define the cryptographic parameters (encryption, authentication, Diffie-Hellman group, and lifetime) for IKE Phase 1 (IKE Crypto Profile) and IKE Phase 2 (IPsec Crypto Profile) of a VPN tunnel.
- IKE Crypto Profile: Defines Phase 1 security associations (SA).
- IPsec Crypto Profile: Defines Phase 2 security associations (SA).
- Ensures secure key exchange and data encryption for VPNs.
- Must match on both ends of the VPN tunnel for successful establishment.
Memory trick: Crypto Profiles for phases of secure tunnels.