Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium

A network security engineer needs to configure a Site-to-Site VPN between a Palo Alto Networks firewall and a third-party VPN gateway. The engineer is setting up the IKE Crypto Profile. Which of the following parameters must be identical on both VPN peers to ensure successful IKE Phase 1 negotiation?

  1. ADPD interval and replay detection
  2. BEncryption algorithm, authentication algorithm, and Diffie-Hellman group
  3. CLocal and remote IP addresses
  4. DNAT traversal and lifetime
Show answer & explanation

Correct answer: B. Encryption algorithm, authentication algorithm, and Diffie-Hellman group

During IKE Phase 1 (Main Mode or Aggressive Mode), the peers negotiate security parameters. The Encryption algorithm, Authentication algorithm, and Diffie-Hellman group must match on both sides for Phase 1 to successfully establish the ISAKMP SA.

Why the other options are wrong

  • A. DPD (Dead Peer Detection) and replay detection are important for tunnel stability and security but are not strictly required to be identical for initial Phase 1 negotiation success.
  • C. Local and remote IP addresses are configured in the IKE Gateway, not the IKE Crypto Profile, and while correct addresses are essential, they are not crypto parameters that must match.
  • D. NAT traversal is a feature that needs to be enabled/disabled consistently, and lifetime is a negotiated value, but these are not the core parameters required to be identical for Phase 1 success.

IKE Crypto Profile (Phase 1)

Defines the cryptographic parameters used to establish the IKE Security Association (SA) during Phase 1 of an IPsec VPN negotiation.

  • Includes encryption algorithm (e.g., AES, 3DES)
  • Includes authentication algorithm (e.g., SHA256, MD5)
  • Includes Diffie-Hellman group for key exchange
  • Must match on both VPN peers

Memory trick: To shake hands securely, both sides need to speak the same secret language.

More Core Concepts questions