nerdexam
Palo_Alto_Networks

PCNSE7 · Question #177

After Migrating from an ASA firewall to a Palo Alto Networks Firewall, the VPN connection between a remote network and the Palo Alto Networks Firewall is not establishing correctly. The following…

The correct answer is D. Update the IPSec Crypto profile for the Vendor IPSec Tunnel from no-pfs to group2. See the full explanation below for the reasoning.

Question

After Migrating from an ASA firewall to a Palo Alto Networks Firewall, the VPN connection between a remote network and the Palo Alto Networks Firewall is not establishing correctly. The following entry is appearing in the logs:

Pfs group mismatched: my:0 peer:2 Which setting should be changed on the Palo Alto Networks Firewall to resolve this error message?

Options

  • AUpdate- the IPSec Crypto profile for the Vendor IPSec Tunnel from group2 to no-pfs.
  • BUpdate the IKE Crypto profile for the Vendor IKE gateway from no pfs to group2.
  • CUpdate the IKE Crypto profile for the Vendor IKE gateway from group2 to no pfs
  • DUpdate the IPSec Crypto profile for the Vendor IPSec Tunnel from no-pfs to group2.

How the community answered

(52 responses)
  • A
    10% (5)
  • B
    6% (3)
  • C
    2% (1)
  • D
    83% (43)

Community Discussion

No community discussion yet for this question.

Full PCNSE7 Practice