nerdexam
Palo_Alto_Networks

PCNSE · Question #693

A network engineer troubleshoots a VPN Phase 2 mismatch and decides that PFS (Perfect Forward Secrecy) needs to be enabled. What action should the engineer take?

The correct answer is C. Select the appropriate DH Group under the IPSec Crypto profile. To resolve a VPN Phase 2 mismatch by enabling Perfect Forward Secrecy (PFS), the engineer must ensure a new Diffie-Hellman (DH) key exchange occurs during Phase 2. This is achieved by configuring the DH group within the IPSec Crypto profile, as PFS in Phase 2 is enabled by…

Submitted by haruto_sh· Apr 18, 2026Deploy and Configure

Question

A network engineer troubleshoots a VPN Phase 2 mismatch and decides that PFS (Perfect Forward Secrecy) needs to be enabled. What action should the engineer take?

Options

  • AAdd an authentication algorithm in the IPSec Crypto profile.
  • BEnable PFS under the IPSec Tunnel advanced options.
  • CSelect the appropriate DH Group under the IPSec Crypto profile.
  • DEnable PFS under the IKE gateway advanced options

How the community answered

(42 responses)
  • A
    5% (2)
  • C
    88% (37)
  • D
    7% (3)

Explanation

To resolve a VPN Phase 2 mismatch by enabling Perfect Forward Secrecy (PFS), the engineer must ensure a new Diffie-Hellman (DH) key exchange occurs during Phase 2. This is achieved by configuring the DH group within the IPSec Crypto profile, as PFS in Phase 2 is enabled by specifying a DH group.

Topics

#VPN#IPSec#PFS#Crypto Profile

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice