PCNSE · Question #728
Phase two of a VPN will not establish a connection. The peer is using a policy-based VPN configuration. What part of the configuration should the engineer verify?
The correct answer is C. Proxy-IDs. Policy-based VPNs define 'interesting traffic' using Proxy IDs (traffic selectors), which specify the local and remote subnets allowed through the tunnel. When a Palo Alto Networks firewall connects to a policy-based VPN peer, Proxy IDs must be explicitly configured to match what
Question
Phase two of a VPN will not establish a connection. The peer is using a policy-based VPN configuration. What part of the configuration should the engineer verify?
Options
- AIKE Crypto Profile
- BSecurity policy
- CProxy-IDs
- DPAN-OS versions
How the community answered
(23 responses)- A4% (1)
- B4% (1)
- C83% (19)
- D9% (2)
Explanation
Policy-based VPNs define 'interesting traffic' using Proxy IDs (traffic selectors), which specify the local and remote subnets allowed through the tunnel. When a Palo Alto Networks firewall connects to a policy-based VPN peer, Proxy IDs must be explicitly configured to match what the peer expects. A mismatch in Proxy IDs is the most common reason IKE Phase 2 (IPsec SA negotiation) fails. IKE Crypto Profiles (Choice A) are Phase 1 parameters. Security policy (Choice B) and PAN-OS versions (Choice D) are not the primary cause of a Phase 2 failure with a policy-based peer.
Topics
Community Discussion
No community discussion yet for this question.