Courseiva
VPN Basics →mediumMultiple Choice

156-215.81.20 VPN Basics Practice Question

An administrator configures a Site-to-Site VPN between two Check Point R81 gateways using a Star community. IKE Phase 1 completes successfully, but IKE Phase 2 fails with the error 'No proposal chosen'. The administrator has verified that the encryption and hash algorithms match on both gateways. Which action should the administrator take to resolve this issue?

⚠ Common exam trap

The trap here is assuming that a successful IKE Phase 1 guarantees that all cryptographic parameters are aligned, overlooking the independent Phase 2 proposal and PFS settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the Diffie-Hellman group configured for IKE Phase 2 (Perfect Forward Secrecy) matches on both gateways.

IKE Phase 2 negotiates the IPsec SA and includes its own set of security parameters, including the Perfect Forward Secrecy (PFS) Diffie-Hellman group. Even if Phase 1 succeeds, a mismatch in the PFS group will cause Phase 2 to fail with 'No proposal chosen'. Aligning the PFS group on both gateways resolves the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensure that the VPN community is configured to use 'One VPN tunnel per subnet pair'.

    Why it's wrong here

    The tunnel-sharing setting affects how many IPsec tunnels are created for multiple subnets, but it does not influence the Phase 2 proposal negotiation. A mismatch in encryption or hash algorithms causes 'No proposal chosen', not the tunnel granularity setting. This change would not resolve the error.

  • ✗

    Confirm that the pre-shared secret is identical on both gateways.

    Why it's wrong here

    A mismatched pre-shared secret would cause IKE Phase 1 authentication to fail, not Phase 2. Since Phase 1 completes successfully, the pre-shared secret is already correct. Changing it would not fix the Phase 2 proposal mismatch and could disrupt the working Phase 1.

  • ✓

    Verify that the Diffie-Hellman group configured for IKE Phase 2 (Perfect Forward Secrecy) matches on both gateways.

    Why this is correct

    IKE Phase 2 (Quick Mode) negotiates IPsec SAs and can use a separate Diffie-Hellman group for Perfect Forward Secrecy. If the PFS group differs between peers, the Phase 2 proposal fails with 'No proposal chosen'. Checking and aligning the PFS group on both gateways directly resolves this mismatch.

  • ✗

    Check that the gateway's VPN domain includes the correct encryption domain.

    Why it's wrong here

    An incorrect VPN domain would cause traffic to be dropped or not encrypted, but it would not trigger a Phase 2 'No proposal chosen' error. The proposal failure indicates an algorithm mismatch, not a topology or encryption domain issue. Adjusting the VPN domain would not fix the negotiation failure.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.