Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsMedium
A network engineer is configuring a Site-to-Site VPN between a Palo Alto Networks firewall and a third-party VPN gateway. During Phase 1 negotiation, the connection fails. The logs indicate a mismatch in the encryption algorithm. Which IKE Crypto Profile parameter should the engineer verify?
- ALifetime
- BEncryption
- CAuthentication
- DDiffie-Hellman Group
Show answer & explanationAnswer & explanation
Correct answer: B. Encryption
Phase 1 negotiation failures related to 'encryption algorithm mismatch' directly point to an issue with the 'Encryption' parameter within the IKE Crypto Profile. This parameter defines the symmetric encryption algorithm used for the IKE SA.
Why the other options are wrong
- A. Lifetime defines how long the IKE SA remains valid, and a mismatch typically leads to rekeying issues, not initial negotiation failure due to algorithm mismatch.
- C. Authentication refers to the method of authenticating peers (e.g., pre-shared key, certificates), not the encryption algorithm.
- D. Diffie-Hellman Group determines the strength of the key exchange, not the symmetric encryption algorithm.
IKE Crypto Profile (Phase 1)
A configuration object in Palo Alto Networks firewalls that defines the cryptographic parameters for the Internet Key Exchange (IKE) Phase 1 negotiation of a VPN tunnel.
- Includes Encryption, Authentication, Diffie-Hellman Group, and Lifetime.
- Must match between VPN peers for successful Phase 1.
- Establishes the secure channel for Phase 2 negotiation.
Memory trick: E.A.D.L. - Encryption, Authentication, DH Group, Lifetime. Don't forget the 'E' for encryption!