PCNSE · Question #391
An administrator receives the following error message: "IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192. 168.33.33/24 type IPv4 address protocol 0 port 0, received…
The correct answer is B. Check whether the VPN peer on one end is set up correctly using policy-based VPN. The VPN peer on one end is using policy-based VPN. You must configure a Proxy ID on the Palo Alto Networks firewall. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/vpns/set-up-site-to-site- vpn/interpret-vpn-error-messages.html
Question
An administrator receives the following error message:
"IKE phase-2 negotiation failed when processing Proxy ID. Received local id 192. 168.33.33/24 type IPv4 address protocol 0 port 0, received remote id 172.16.33.33/24 type IPv4 address protocol 0 port 0." How should the administrator identify the root cause of this error message?
Options
- AVerify that the IP addresses can be pinged and that routing issues are not causing the connection
- BCheck whether the VPN peer on one end is set up correctly using policy-based VPN.
- CIn the IKE Gateway configuration, verify that the IP address for each VPN peer is accurate.
- DIn the IPSec Crypto profile configuration, verify that PFS is either enabled on both VPN peers or
How the community answered
(32 responses)- A6% (2)
- B78% (25)
- C3% (1)
- D13% (4)
Explanation
The VPN peer on one end is using policy-based VPN. You must configure a Proxy ID on the Palo Alto Networks firewall. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/vpns/set-up-site-to-site- vpn/interpret-vpn-error-messages.html
Topics
Community Discussion
No community discussion yet for this question.