Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network security engineer is troubleshooting a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party VPN gateway. Phase 1 of IKE is failing to establish. The firewall logs indicate 'Phase 1 negotiation failed due to no acceptable proposal'. Which configuration parameter is MOST likely mismatched between the two VPN peers?

  1. AThe IPSec crypto profile settings (e.g., encryption, authentication, DH group).
  2. BThe IKE crypto profile settings (e.g., encryption, authentication, DH group).
  3. CThe proxy IDs (local and remote networks).
  4. DThe pre-shared key.
Show answer & explanation

Correct answer: B. The IKE crypto profile settings (e.g., encryption, authentication, DH group).

The error message 'Phase 1 negotiation failed due to no acceptable proposal' specifically points to a mismatch in the IKE (Phase 1) crypto profile settings. These settings define how the secure channel for key exchange is established.

Why the other options are wrong

  • A. IPSec crypto profile settings are used for Phase 2, which occurs after Phase 1 has successfully established the secure channel.
  • C. Proxy IDs are part of Phase 2 (IPSec) negotiation, not Phase 1 (IKE).
  • D. A mismatched pre-shared key would typically result in an authentication failure, not a proposal mismatch.

IKE Phase 1 Troubleshooting

IKE Phase 1 establishes a secure, authenticated channel (IKE SA) for peer authentication and secure exchange of keys for Phase 2. Mismatched crypto settings prevent this initial secure channel from forming.

  • IKE Phase 1 (Main Mode/Aggressive Mode) creates a secure tunnel for IKE negotiations.
  • Requires matching encryption, authentication, and DH group.
  • 'No acceptable proposal' indicates a mismatch in these settings.

Memory trick: First handshake failed? Check the secret club rules (crypto profile)!

More Troubleshoot questions