Courseiva
VPN Basics →mediumMultiple Choice

156-215.81.20 VPN Basics Practice Question

An administrator configures a Site-to-Site VPN between two Check Point R81 Security Gateways using IKEv2. The VPN tunnel establishes successfully, but after several hours, users report that the tunnel is dropping and re-establishing repeatedly. Logs show 'IKEv2 Child SA rekey failed' and 'Received INVALID_KE_PAYLOAD'. Which action should the administrator take to resolve this?

⚠ Common exam trap

The trap here is assuming that any IKEv2 rekey failure is due to lifetime or authentication settings, rather than checking the Diffie-Hellman group compatibility in Phase 2.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that both gateways have compatible Diffie-Hellman groups configured for Phase 2 (IPsec) and adjust the encryption properties in the VPN Community.

The INVALID_KE_PAYLOAD notification during IKEv2 Child SA rekey indicates that the proposed Diffie-Hellman group is not acceptable to the peer. This typically occurs when the Phase 2 encryption properties in the VPN Community are misaligned. Ensuring both gateways use the same DH group for IPsec resolves the rekey failure and stabilizes the tunnel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable Perfect Forward Secrecy (PFS) on the VPN Community to simplify rekeying.

    Why it's wrong here

    Disabling PFS might avoid the DH exchange during rekey, but it weakens security and is not the recommended fix. The error specifically points to a DH group mismatch; disabling PFS would mask the problem without correcting the configuration. Moreover, PFS is often required by security policies.

  • ✗

    Change the IKEv2 authentication method from certificates to pre-shared secret to avoid DH group issues.

    Why it's wrong here

    Authentication method (certificates vs. pre-shared secret) is independent of the DH group used for key exchange. The INVALID_KE_PAYLOAD error is about the Key Exchange payload, not authentication. Changing authentication would not resolve the DH group mismatch and could introduce other issues.

  • ✓

    Verify that both gateways have compatible Diffie-Hellman groups configured for Phase 2 (IPsec) and adjust the encryption properties in the VPN Community.

    Why this is correct

    The INVALID_KE_PAYLOAD error during Child SA rekey indicates a mismatch in the Diffie-Hellman group used for Phase 2. In IKEv2, the responder must support the DH group proposed by the initiator. Ensuring both gateways use the same DH group in the IPsec encryption properties of the VPN Community resolves the rekey failure.

  • ✗

    Increase the IKEv2 SA lifetime on both gateways to prevent frequent renegotiation.

    Why it's wrong here

    Increasing the IKEv2 SA lifetime might reduce the frequency of rekeys, but it does not fix the underlying DH group mismatch that causes INVALID_KE_PAYLOAD. The tunnel would still fail when rekey eventually occurs, and this action does not address the root cause.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.