Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium
A security engineer is troubleshooting a site-to-site VPN connection between a Palo Alto Networks firewall and a third-party device. Phase 1 of the IKE negotiation is failing. The firewall logs indicate a 'NO_PROPOSAL_CHOSEN' error. Which of the following is the most likely cause?
- AMismatch in the IKE Crypto Profile parameters (e.g., encryption, authentication, DH group).
- BIncorrect proxy IDs configured in the IPsec Tunnel.
- CMismatch in the pre-shared key.
- DReachability issue to the peer's external interface.
Show answer & explanationAnswer & explanation
Correct answer: A. Mismatch in the IKE Crypto Profile parameters (e.g., encryption, authentication, DH group).
A 'NO_PROPOSAL_CHOSEN' error during IKE Phase 1 negotiation specifically indicates that the two VPN peers could not agree on a common set of security parameters (encryption, authentication, Diffie-Hellman group) defined in their respective IKE Crypto Profiles. They are unable to find a mutually acceptable proposal.
Why the other options are wrong
- B. Incorrect proxy IDs (or interesting traffic) are part of Phase 2 (IPsec SA negotiation) and would cause Phase 2 to fail, not Phase 1.
- C. A pre-shared key mismatch would typically result in an 'AUTHENTICATION_FAILED' error, not 'NO_PROPOSAL_CHOSEN'.
- D. A reachability issue would prevent any IKE messages from being exchanged, resulting in no response or timeout, rather than a 'NO_PROPOSAL_CHOSEN' error which implies messages were exchanged but no agreement reached.
IKE Crypto Profile Mismatch
A common cause of 'NO_PROPOSAL_CHOSEN' errors in VPNs, occurring when VPN peers cannot agree on the IKE Phase 1 security parameters (encryption, authentication, DH group).
- Causes IKE Phase 1 negotiation failure.
- Parameters must match exactly on both sides.
- Includes encryption algorithm, authentication algorithm, and Diffie-Hellman group.
Memory trick: No proposal chosen? Check your crypto, then you're golden!