Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootEasy
A network security engineer is troubleshooting a site-to-site VPN tunnel that is failing to establish. The logs show 'IKE phase-1 negotiation failed because of IPsec-VPN local ID mismatch'. Which configuration parameter is most likely incorrect?
- AEncryption algorithm
- BLocal IKE Gateway Identification
- CPreshared key
- DAuthentication algorithm
Show answer & explanationAnswer & explanation
Correct answer: B. Local IKE Gateway Identification
The log message explicitly states 'local ID mismatch', directly pointing to an issue with the Local IKE Gateway Identification setting on the Palo Alto Networks firewall.
Why the other options are wrong
- A. Encryption algorithm mismatch would prevent SA establishment but not typically cause an ID mismatch error.
- C. Preshared key mismatch would typically result in an authentication failure, not an ID mismatch.
- D. Authentication algorithm mismatch would prevent SA establishment but not typically cause an ID mismatch error.
IKE Local ID
The Local IKE Gateway Identification is a unique identifier used by an IKE gateway to identify itself to its peer during Phase 1 negotiation.
- Must match the remote peer's configured remote ID.
- Can be IP address, FQDN, or user FQDN.
- Crucial for successful IKE Phase 1 establishment.
Memory trick: Identify the ID to untie the VPN knot.