Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium
A network security engineer is designing an IPsec VPN tunnel between a Palo Alto Networks firewall and a remote branch office. The requirement is to ensure the highest level of encryption and integrity for the data in transit during Phase 2 (IPsec SA negotiation). Which component should be configured to specify these security parameters?
- AIPsec Crypto Profile
- BTunnel Interface
- CIKE Crypto Profile
- DIKE Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. IPsec Crypto Profile
The IPsec Crypto Profile is specifically configured to define the security parameters for Phase 2 (IPsec SA negotiation) of an IPsec VPN tunnel. This profile specifies the encryption algorithm (e.g., AES256), authentication algorithm (e.g., SHA256), and lifetime for the actual data encryption and integrity of the VPN tunnel. The IKE Crypto Profile is for Phase 1.
Why the other options are wrong
- B. The Tunnel Interface is a logical interface that routes traffic into the VPN tunnel but does not define the cryptographic parameters.
- C. The IKE Crypto Profile defines the security parameters for Phase 1 (IKE SA negotiation), which secures the control channel, not the data channel.
- D. The IKE Gateway defines the peer IP, pre-shared key, and references the IKE Crypto Profile, but doesn't define Phase 2 parameters.
IPsec Crypto Profile
An IPsec Crypto Profile defines the security parameters for Phase 2 (IPsec SA negotiation) of an IPsec VPN tunnel, including encryption algorithm, authentication algorithm, and SA lifetime, to protect data in transit.
- Configures Phase 2 (IPsec SA) parameters.
- Specifies data encryption (e.g., AES) and integrity (e.g., SHA).
- Ensures confidentiality and integrity of user data over the VPN.
Memory trick: IKE for Control, IPsec for Data: Two Phases, Two Profiles.