156-215.81.20 VPN Basics Practice Question
An administrator configures a Site-to-Site VPN between two Check Point R81 gateways using a Star community. IKE Phase 1 completes successfully, but IKE Phase 2 fails with the error 'No proposal chosen'. The administrator has verified that the encryption and hash algorithms match on both gateways. Which action should the administrator take to resolve this issue?
⚠ Common exam trap
The trap here is assuming that a successful IKE Phase 1 guarantees that all cryptographic parameters are aligned, overlooking the independent Phase 2 proposal and PFS settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the Diffie-Hellman group configured for IKE Phase 2 (Perfect Forward Secrecy) matches on both gateways.
IKE Phase 2 negotiates the IPsec SA and includes its own set of security parameters, including the Perfect Forward Secrecy (PFS) Diffie-Hellman group. Even if Phase 1 succeeds, a mismatch in the PFS group will cause Phase 2 to fail with 'No proposal chosen'. Aligning the PFS group on both gateways resolves the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure that the VPN community is configured to use 'One VPN tunnel per subnet pair'.
Why it's wrong here
The tunnel-sharing setting affects how many IPsec tunnels are created for multiple subnets, but it does not influence the Phase 2 proposal negotiation. A mismatch in encryption or hash algorithms causes 'No proposal chosen', not the tunnel granularity setting. This change would not resolve the error.
- ✗
Confirm that the pre-shared secret is identical on both gateways.
Why it's wrong here
A mismatched pre-shared secret would cause IKE Phase 1 authentication to fail, not Phase 2. Since Phase 1 completes successfully, the pre-shared secret is already correct. Changing it would not fix the Phase 2 proposal mismatch and could disrupt the working Phase 1.
- ✓
Verify that the Diffie-Hellman group configured for IKE Phase 2 (Perfect Forward Secrecy) matches on both gateways.
Why this is correct
IKE Phase 2 (Quick Mode) negotiates IPsec SAs and can use a separate Diffie-Hellman group for Perfect Forward Secrecy. If the PFS group differs between peers, the Phase 2 proposal fails with 'No proposal chosen'. Checking and aligning the PFS group on both gateways directly resolves this mismatch.
- ✗
Check that the gateway's VPN domain includes the correct encryption domain.
Why it's wrong here
An incorrect VPN domain would cause traffic to be dropped or not encrypted, but it would not trigger a Phase 2 'No proposal chosen' error. The proposal failure indicates an algorithm mismatch, not a topology or encryption domain issue. Adjusting the VPN domain would not fix the negotiation failure.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.