nerdexam
Palo_Alto_Networks

PCNSE · Question #728

Phase two of a VPN will not establish a connection. The peer is using a policy-based VPN configuration. What part of the configuration should the engineer verify?

The correct answer is C. Proxy-IDs. Policy-based VPNs define 'interesting traffic' using Proxy IDs (traffic selectors), which specify the local and remote subnets allowed through the tunnel. When a Palo Alto Networks firewall connects to a policy-based VPN peer, Proxy IDs must be explicitly configured to match what

Submitted by daniela_cl· Apr 18, 2026Configuration Troubleshooting

Question

Phase two of a VPN will not establish a connection. The peer is using a policy-based VPN configuration. What part of the configuration should the engineer verify?

Options

  • AIKE Crypto Profile
  • BSecurity policy
  • CProxy-IDs
  • DPAN-OS versions

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    83% (19)
  • D
    9% (2)

Explanation

Policy-based VPNs define 'interesting traffic' using Proxy IDs (traffic selectors), which specify the local and remote subnets allowed through the tunnel. When a Palo Alto Networks firewall connects to a policy-based VPN peer, Proxy IDs must be explicitly configured to match what the peer expects. A mismatch in Proxy IDs is the most common reason IKE Phase 2 (IPsec SA negotiation) fails. IKE Crypto Profiles (Choice A) are Phase 1 parameters. Security policy (Choice B) and PAN-OS versions (Choice D) are not the primary cause of a Phase 2 failure with a policy-based peer.

Topics

#VPN#IPsec#Phase 2#Proxy-ID

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice