nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #3

After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish. Which of the following actions…

The correct answer is B. Configure the Proxy IDs to match the Cisco ASA configuration. IPSec tunnel establishment involves two phases. Phase 1 (IKE) negotiates the control channel; Phase 2 (IPSec) negotiates the data channel using 'traffic selectors' that define which traffic is protected. Cisco ASA uses policy-based VPN with crypto ACLs to define interesting…

Implementing and Troubleshooting VPNs

Question

After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish. Which of the following actions will resolve this issue?

Options

  • AEnsure that an active static or dynamic route exists for the VPN peer with next hop as the tunnel
  • BConfigure the Proxy IDs to match the Cisco ASA configuration.
  • CCheck that IPSec is enabled in the management profile on the external interface.
  • DValidate the tunnel interface VLAN against the peer's configuration.

How the community answered

(36 responses)
  • B
    92% (33)
  • C
    3% (1)
  • D
    6% (2)

Explanation

IPSec tunnel establishment involves two phases. Phase 1 (IKE) negotiates the control channel; Phase 2 (IPSec) negotiates the data channel using 'traffic selectors' that define which traffic is protected. Cisco ASA uses policy-based VPN with crypto ACLs to define interesting traffic. Palo Alto Networks NGFWs default to route-based VPN where Proxy IDs (local subnet, remote subnet, and protocol) serve as the traffic selectors. When connecting a PAN firewall to a policy-based device like the ASA, the Proxy IDs on the PAN side MUST exactly match the crypto ACL entries on the ASA side. A mismatch causes Phase 2 negotiation to fail with 'no matching proposal' errors. Option A is incorrect because the next hop for a VPN peer should be the external interface, not the tunnel interface. Option C is wrong because IPSec is not enabled via a management profile. Option D is a distractor - tunnel interfaces do not use VLANs.

Topics

#IPSec VPN#Proxy ID#Tunnel Troubleshooting#Cross-Vendor VPN

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice