Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootEasy
A network engineer is troubleshooting a site-to-site VPN tunnel that is failing to establish. The logs show 'IKE Phase 1 negotiation failed: No proposal chosen'. What is the most likely cause for this error?
- AMismatch in NAT traversal settings.
- BIncorrect proxy IDs (local and remote subnets).
- CIncorrect pre-shared key.
- DMismatch in IKE Crypto Profile settings (encryption, authentication, DH group).
Show answer & explanationAnswer & explanation
Correct answer: D. Mismatch in IKE Crypto Profile settings (encryption, authentication, DH group).
The error message 'No proposal chosen' during IKE Phase 1 directly indicates that the IKE Crypto Profiles on both VPN peers do not have a common set of encryption, authentication, and Diffie-Hellman (DH) group algorithms that they can agree upon. These parameters must match for Phase 1 to succeed.
Why the other options are wrong
- A. NAT traversal issues typically manifest later or with different error messages, often related to UDP encapsulation, not 'No proposal chosen'.
- B. Incorrect proxy IDs are part of IKE Phase 2 (IPsec tunnel establishment), not IKE Phase 1 negotiation.
- C. An incorrect pre-shared key would result in an 'Authentication failed' or similar error, not 'No proposal chosen'.
IKE Phase 1 Proposal Mismatch
IKE Phase 1 requires both VPN peers to agree on a common set of cryptographic algorithms (encryption, authentication, DH group) defined in their IKE Crypto Profiles.
- Error 'No proposal chosen' indicates this mismatch.
- Occurs during IKE Phase 1, before authentication.
- All parameters (encryption, auth, DH group) must have at least one common value.
Memory trick: IKE Phase 1: Key Exchange, Keep Everything Consistent.