Palo_Alto_Networks
PCNSE7 · Question #177
After Migrating from an ASA firewall to a Palo Alto Networks Firewall, the VPN connection between a remote network and the Palo Alto Networks Firewall is not establishing correctly. The following…
The correct answer is D. Update the IPSec Crypto profile for the Vendor IPSec Tunnel from no-pfs to group2. See the full explanation below for the reasoning.
Question
After Migrating from an ASA firewall to a Palo Alto Networks Firewall, the VPN connection between a remote network and the Palo Alto Networks Firewall is not establishing correctly. The following entry is appearing in the logs:
Pfs group mismatched: my:0 peer:2 Which setting should be changed on the Palo Alto Networks Firewall to resolve this error message?
Options
- AUpdate- the IPSec Crypto profile for the Vendor IPSec Tunnel from group2 to no-pfs.
- BUpdate the IKE Crypto profile for the Vendor IKE gateway from no pfs to group2.
- CUpdate the IKE Crypto profile for the Vendor IKE gateway from group2 to no pfs
- DUpdate the IPSec Crypto profile for the Vendor IPSec Tunnel from no-pfs to group2.
How the community answered
(52 responses)- A10% (5)
- B6% (3)
- C2% (1)
- D83% (43)
Community Discussion
No community discussion yet for this question.