Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootEasy

A network security engineer is troubleshooting a site-to-site VPN tunnel that is failing to establish between a Palo Alto Networks firewall and a third-party device. The tunnel logs show 'No proposal chosen'. Which of the following is the MOST likely cause?

  1. AMismatch in IKE Phase 2 (IPsec) security parameters.
  2. BIncorrect pre-shared key.
  3. CIncorrect proxy IDs.
  4. DMismatch in IKE Phase 1 (ISAKMP) security parameters.
Show answer & explanation

Correct answer: D. Mismatch in IKE Phase 1 (ISAKMP) security parameters.

The 'No proposal chosen' error typically indicates a mismatch in the security parameters negotiated during IKE Phase 1. This prevents the initial secure channel from being established.

Why the other options are wrong

  • A. IKE Phase 2 parameters are negotiated after Phase 1 is successfully established. If Phase 1 fails, Phase 2 parameters are not yet relevant.
  • B. An incorrect pre-shared key would likely result in an authentication failure, not a 'No proposal chosen' error.
  • C. Incorrect proxy IDs (or interesting traffic) would prevent traffic from passing through the tunnel, but not prevent Phase 1 from establishing.

IKE Phase 1 Mismatch

IKE Phase 1 (Internet Key Exchange Phase 1) is the initial negotiation stage of a VPN tunnel where security parameters are agreed upon to establish a secure channel for subsequent negotiations.

  • Establishes the ISAKMP SA.
  • Negotiates encryption, authentication, DH group, and lifetime.
  • Common error: 'No proposal chosen'.

Memory trick: VPN tunnels need a strong handshake before they can talk secrets.

More Troubleshoot questions