156-215.81.20 VPN Basics Practice Question
An administrator configures a Site-to-Site VPN between two Check Point R81 Security Gateways using IKEv2. The VPN tunnel establishes successfully, but after several hours, users report that the tunnel is dropping and re-establishing repeatedly. Logs show 'IKEv2 Child SA rekey failed' and 'Received INVALID_KE_PAYLOAD'. Which action should the administrator take to resolve this?
⚠ Common exam trap
The trap here is assuming that any IKEv2 rekey failure is due to lifetime or authentication settings, rather than checking the Diffie-Hellman group compatibility in Phase 2.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that both gateways have compatible Diffie-Hellman groups configured for Phase 2 (IPsec) and adjust the encryption properties in the VPN Community.
The INVALID_KE_PAYLOAD notification during IKEv2 Child SA rekey indicates that the proposed Diffie-Hellman group is not acceptable to the peer. This typically occurs when the Phase 2 encryption properties in the VPN Community are misaligned. Ensuring both gateways use the same DH group for IPsec resolves the rekey failure and stabilizes the tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable Perfect Forward Secrecy (PFS) on the VPN Community to simplify rekeying.
Why it's wrong here
Disabling PFS might avoid the DH exchange during rekey, but it weakens security and is not the recommended fix. The error specifically points to a DH group mismatch; disabling PFS would mask the problem without correcting the configuration. Moreover, PFS is often required by security policies.
- ✗
Change the IKEv2 authentication method from certificates to pre-shared secret to avoid DH group issues.
Why it's wrong here
Authentication method (certificates vs. pre-shared secret) is independent of the DH group used for key exchange. The INVALID_KE_PAYLOAD error is about the Key Exchange payload, not authentication. Changing authentication would not resolve the DH group mismatch and could introduce other issues.
- ✓
Verify that both gateways have compatible Diffie-Hellman groups configured for Phase 2 (IPsec) and adjust the encryption properties in the VPN Community.
Why this is correct
The INVALID_KE_PAYLOAD error during Child SA rekey indicates a mismatch in the Diffie-Hellman group used for Phase 2. In IKEv2, the responder must support the DH group proposed by the initiator. Ensuring both gateways use the same DH group in the IPsec encryption properties of the VPN Community resolves the rekey failure.
- ✗
Increase the IKEv2 SA lifetime on both gateways to prevent frequent renegotiation.
Why it's wrong here
Increasing the IKEv2 SA lifetime might reduce the frequency of rekeys, but it does not fix the underlying DH group mismatch that causes INVALID_KE_PAYLOAD. The tunnel would still fail when rekey eventually occurs, and this action does not address the root cause.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.