Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootEasy

A network engineer is troubleshooting a site-to-site VPN tunnel that is failing to establish. The logs show 'IKE Phase 1 negotiation failed: No proposal chosen'. What is the most likely cause for this error?

  1. AMismatch in NAT traversal settings.
  2. BIncorrect proxy IDs (local and remote subnets).
  3. CIncorrect pre-shared key.
  4. DMismatch in IKE Crypto Profile settings (encryption, authentication, DH group).
Show answer & explanation

Correct answer: D. Mismatch in IKE Crypto Profile settings (encryption, authentication, DH group).

The error message 'No proposal chosen' during IKE Phase 1 directly indicates that the IKE Crypto Profiles on both VPN peers do not have a common set of encryption, authentication, and Diffie-Hellman (DH) group algorithms that they can agree upon. These parameters must match for Phase 1 to succeed.

Why the other options are wrong

  • A. NAT traversal issues typically manifest later or with different error messages, often related to UDP encapsulation, not 'No proposal chosen'.
  • B. Incorrect proxy IDs are part of IKE Phase 2 (IPsec tunnel establishment), not IKE Phase 1 negotiation.
  • C. An incorrect pre-shared key would result in an 'Authentication failed' or similar error, not 'No proposal chosen'.

IKE Phase 1 Proposal Mismatch

IKE Phase 1 requires both VPN peers to agree on a common set of cryptographic algorithms (encryption, authentication, DH group) defined in their IKE Crypto Profiles.

  • Error 'No proposal chosen' indicates this mismatch.
  • Occurs during IKE Phase 1, before authentication.
  • All parameters (encryption, auth, DH group) must have at least one common value.

Memory trick: IKE Phase 1: Key Exchange, Keep Everything Consistent.

More Troubleshoot questions