ExamGecko
Question list
Search
Search

Question 298 - 156-315.81 discussion

Report
Export

When attempting to start a VPN tunnel, in the logs the error ''no proposal chosen'' is seen numerous times. No other VPN-related entries are present.

Which phase of the VPN negotiations has failed?

A.
IKE Phase 1
Answers
A.
IKE Phase 1
B.
IPSEC Phase 2
Answers
B.
IPSEC Phase 2
C.
IPSEC Phase 1
Answers
C.
IPSEC Phase 1
D.
IKE Phase 2
Answers
D.
IKE Phase 2
Suggested answer: A

Explanation:

The error ''no proposal chosen'' indicates that the VPN gateway did not find a matching proposal for the IKE Phase 1 negotiation. This phase is responsible for establishing a secure channel between the VPN peers, using a pre-shared secret or a certificate. The proposal consists of parameters such as encryption algorithm, hash algorithm, Diffie-Hellman group, and lifetime.If the VPN gateway does not receive a proposal that matches its own configuration, it will reject the connection attempt and log the error ''no proposal chosen''1.

To troubleshoot this issue, one should verify that the VPN peers have the same IKE Phase 1 settings, such as:

The same pre-shared secret or certificate

The same encryption algorithm (e.g., AES-256)

The same hash algorithm (e.g., SHA-256)

The same Diffie-Hellman group (e.g., Group 14)

The same lifetime (e.g., 86400 seconds)

One can use the commandvpn tuon the VPN gateway to view the current IKE Phase 1 settings and compare them with the other peer.Alternatively, one can use the SmartConsole to check the VPN community properties and the gateway object properties for the IKE Phase 1 settings2.

asked 16/09/2024
Darren Bajada
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first