CAS-005 · Question #380
A security technician is trying to connect a remote site to the central office over a site-to-site VPN. The technician has verified the source and destination IP addresses are correct, but the…
The correct answer is A. The IKE hashing algorithm uses different key lengths on each VPN device. The error message "An error has occurred during Phase 1 handshake. Deleting keys and retrying..." indicates an issue during the IKE (Internet Key Exchange) Phase 1 handshake. One common cause for failure at this stage is a mismatch in the hashing algorithm or key length used on…
Question
A security technician is trying to connect a remote site to the central office over a site-to-site VPN. The technician has verified the source and destination IP addresses are correct, but the technician is unable to get the remote site to connect. The following error message keeps repeating:
An error has occurred during Phase 1 handshake. Deleting keys and retrying... Which of the following is most likely the reason the connection is failing?
Options
- AThe IKE hashing algorithm uses different key lengths on each VPN device.
- BThe IPSec settings allow more than one cipher suite on both devices.
- CThe Diffie-Hellman group on both sides matches but is a legacy group.
- DThe remote VPN is attempting to connect with a protocol other than SSL/TLS.
How the community answered
(44 responses)- A82% (36)
- B7% (3)
- C9% (4)
- D2% (1)
Explanation
The error message "An error has occurred during Phase 1 handshake. Deleting keys and retrying..." indicates an issue during the IKE (Internet Key Exchange) Phase 1 handshake. One common cause for failure at this stage is a mismatch in the hashing algorithm or key length used on both devices. If the IKE hashing algorithm or key lengths differ between the two devices, they will not be able to establish a secure connection.
Community Discussion
No community discussion yet for this question.