Courseiva

CCSM Advanced VPN Troubleshooting Practice Question

A Check Point Security Gateway is experiencing intermittent VPN tunnel failures. The logs show 'Phase 2 completion failed' with the reason 'No proposal chosen'. Which of the following is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates confuse Phase 2 proposal mismatch with Phase 1 issues like shared secret or firewall blocks, even though the error clearly points to Phase 2 negotiation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IPsec Phase 2 proposal (encryption and integrity algorithms) does not match between peers.

The 'No proposal chosen' error during Phase 2 completion indicates that the gateways could not agree on the IPsec parameters for the Phase 2 SA. This is most often caused by mismatched encryption or integrity algorithms in the Phase 2 proposal. Each gateway sends its list of supported proposals; if there is no common proposal, the negotiation fails. Verifying and aligning the Phase 2 proposals on both peers resolves the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VPN tunnel is blocked by a firewall rule.

    Why it's wrong here

    A firewall rule blocking the VPN tunnel would prevent the tunnel from establishing entirely or cause traffic to be dropped, but it would not produce a 'No proposal chosen' error during Phase 2. That error is specific to the IPsec proposal negotiation, indicating a mismatch in algorithms, not a policy block. Firewall issues would typically manifest as drops or timeouts, not proposal rejection.

  • ✗

    The Phase 1 shared secret is incorrect.

    Why it's wrong here

    An incorrect Phase 1 shared secret would cause Phase 1 authentication to fail, typically with a 'Phase 1 completion failed' or 'Authentication failed' message. Since the error is specifically about Phase 2 completion, Phase 1 must have succeeded. Therefore, the shared secret is not the issue.

  • ✓

    The IPsec Phase 2 proposal (encryption and integrity algorithms) does not match between peers.

    Why this is correct

    The 'No proposal chosen' error in Phase 2 indicates that the two gateways could not agree on a set of IPsec parameters for the Phase 2 SA. This is typically due to mismatched encryption or integrity algorithms in the Phase 2 proposal. Each peer offers its configured proposals, and if there is no overlap, the negotiation fails. Checking and aligning the Phase 2 proposals on both gateways resolves this issue.

  • ✗

    The peer gateway is using a different Diffie-Hellman group for Phase 2.

    Why it's wrong here

    While a Diffie-Hellman group mismatch can cause Phase 2 failures, the error message would typically be different, such as 'Diffie-Hellman group mismatch' or 'Invalid KE payload'. 'No proposal chosen' specifically points to a mismatch in the encryption and integrity algorithms (the proposal), not the DH group. However, if PFS is enabled, the DH group is part of the proposal, so a mismatch there could also result in 'No proposal chosen'. But the most common cause is algorithm mismatch.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every CCSM question from scratch — 219 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.