Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootHard
A network engineer is troubleshooting a site-to-site VPN tunnel between a Palo Alto Networks firewall and a third-party device. IKE Phase 1 establishes successfully, but IKE Phase 2 consistently fails with 'No proposal chosen' in the logs. Which two parameters are most likely mismatched between the two VPN peers?
- AIKE Gateway type and Interface
- BPreshared key and Local IKE Gateway Identification
- CAuthentication algorithm and DH Group for Phase 2
- DIPsec Proxy ID and Encryption algorithm
Show answer & explanationAnswer & explanation
Correct answer: C. Authentication algorithm and DH Group for Phase 2
The error 'No proposal chosen' during IKE Phase 2 directly indicates a mismatch in the IPsec Crypto Profile parameters. Specifically, the Authentication algorithm (e.g., SHA256, MD5) and the Diffie-Hellman (DH) Group (e.g., group 14, 19, 20) are common culprits when a proposal cannot be mutually agreed upon for Phase 2.
Why the other options are wrong
- A. IKE Gateway type and Interface are Phase 1 configuration elements. Mismatches here would prevent Phase 1 from establishing.
- B. Preshared key and Local IKE Gateway Identification are Phase 1 parameters. Mismatches here would prevent Phase 1 from establishing, not Phase 2.
- D. IPsec Proxy ID mismatch would cause traffic not to flow or 'no route' errors, not 'No proposal chosen' in Phase 2. Encryption algorithm is a Phase 2 parameter, but pairing it with Proxy ID makes this option less precise.
IKE Phase 2 Proposal Mismatch
The 'No proposal chosen' error during IKE Phase 2 (IPsec SA negotiation) indicates that the IPsec Crypto Profiles on both VPN peers do not have a mutually acceptable set of security parameters.
- Commonly due to mismatches in encryption algorithm, authentication algorithm, or DH group.
- Phase 1 must be successful for Phase 2 to begin.
- Check IPsec Crypto Profile settings on both sides.
Memory trick: Phase 2 needs a perfect pair, or it won't share.