Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium
A network security engineer needs to configure a Site-to-Site VPN between a Palo Alto Networks firewall and a third-party VPN gateway. The engineer is setting up the IKE Crypto Profile. Which of the following parameters must be identical on both VPN peers to ensure successful IKE Phase 1 negotiation?
- ADPD interval and replay detection
- BEncryption algorithm, authentication algorithm, and Diffie-Hellman group
- CLocal and remote IP addresses
- DNAT traversal and lifetime
Show answer & explanationAnswer & explanation
Correct answer: B. Encryption algorithm, authentication algorithm, and Diffie-Hellman group
During IKE Phase 1 (Main Mode or Aggressive Mode), the peers negotiate security parameters. The Encryption algorithm, Authentication algorithm, and Diffie-Hellman group must match on both sides for Phase 1 to successfully establish the ISAKMP SA.
Why the other options are wrong
- A. DPD (Dead Peer Detection) and replay detection are important for tunnel stability and security but are not strictly required to be identical for initial Phase 1 negotiation success.
- C. Local and remote IP addresses are configured in the IKE Gateway, not the IKE Crypto Profile, and while correct addresses are essential, they are not crypto parameters that must match.
- D. NAT traversal is a feature that needs to be enabled/disabled consistently, and lifetime is a negotiated value, but these are not the core parameters required to be identical for Phase 1 success.
IKE Crypto Profile (Phase 1)
Defines the cryptographic parameters used to establish the IKE Security Association (SA) during Phase 1 of an IPsec VPN negotiation.
- Includes encryption algorithm (e.g., AES, 3DES)
- Includes authentication algorithm (e.g., SHA256, MD5)
- Includes Diffie-Hellman group for key exchange
- Must match on both VPN peers
Memory trick: To shake hands securely, both sides need to speak the same secret language.