Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium
A network security engineer is troubleshooting a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party VPN gateway. Phase 1 of IKE is failing to establish. The firewall logs indicate 'Phase 1 negotiation failed due to no acceptable proposal'. Which configuration parameter is MOST likely mismatched between the two VPN peers?
- AThe IPSec crypto profile settings (e.g., encryption, authentication, DH group).
- BThe IKE crypto profile settings (e.g., encryption, authentication, DH group).
- CThe proxy IDs (local and remote networks).
- DThe pre-shared key.
Show answer & explanationAnswer & explanation
Correct answer: B. The IKE crypto profile settings (e.g., encryption, authentication, DH group).
The error message 'Phase 1 negotiation failed due to no acceptable proposal' specifically points to a mismatch in the IKE (Phase 1) crypto profile settings. These settings define how the secure channel for key exchange is established.
Why the other options are wrong
- A. IPSec crypto profile settings are used for Phase 2, which occurs after Phase 1 has successfully established the secure channel.
- C. Proxy IDs are part of Phase 2 (IPSec) negotiation, not Phase 1 (IKE).
- D. A mismatched pre-shared key would typically result in an authentication failure, not a proposal mismatch.
IKE Phase 1 Troubleshooting
IKE Phase 1 establishes a secure, authenticated channel (IKE SA) for peer authentication and secure exchange of keys for Phase 2. Mismatched crypto settings prevent this initial secure channel from forming.
- IKE Phase 1 (Main Mode/Aggressive Mode) creates a secure tunnel for IKE negotiations.
- Requires matching encryption, authentication, and DH group.
- 'No acceptable proposal' indicates a mismatch in these settings.
Memory trick: First handshake failed? Check the secret club rules (crypto profile)!