Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium
A network engineer is configuring a Site-to-Site VPN between a Palo Alto Networks firewall and a third-party VPN gateway. The third-party device requires the use of Diffie-Hellman Group 14 for IKE Phase 1. Which configuration setting on the Palo Alto Networks firewall must be adjusted to ensure successful Phase 1 establishment?
- AThe IKE Gateway's Authentication Profile.
- BThe Tunnel Interface's Security Zone.
- CThe IKE Crypto Profile's Diffie-Hellman Group.
- DThe IPsec Crypto Profile's Protocol.
Show answer & explanationAnswer & explanation
Correct answer: C. The IKE Crypto Profile's Diffie-Hellman Group.
Diffie-Hellman (DH) Group selection is a critical parameter for IKE Phase 1, used to establish a shared secret key securely. The IKE Crypto Profile on the Palo Alto Networks firewall must be configured to use the same DH Group (in this case, Group 14) as the peer device for successful Phase 1 negotiation.
Why the other options are wrong
- A. Authentication Profile defines methods like pre-shared key or certificates, not DH groups.
- B. The Tunnel Interface's Security Zone is for policy application and routing, not for cryptographic parameters of the VPN tunnel itself.
- D. IPsec Crypto Profile's Protocol defines ESP/AH and encryption/authentication algorithms for Phase 2, not DH groups for Phase 1.
IKE Phase 1 Diffie-Hellman Group
The Diffie-Hellman (DH) group specified in the IKE Crypto Profile determines the strength of the key exchange used to establish the IKE SA (Phase 1) during VPN tunnel negotiation, and must match between VPN peers.
- Critical for IKE Phase 1 key exchange.
- Must match on both VPN peers.
- Higher group numbers generally offer stronger security.
Memory trick: Phase 1: IKE Crypto Profile needs DH Group Match.