Courseiva

CCSM Advanced VPN Troubleshooting Practice Question

An administrator is troubleshooting a site-to-site VPN between two Security Gateways. Phase 1 completes, but Phase 2 fails immediately. The administrator runs 'vpn debug ikeon', reproduces the failure, and inspects $FWDIR/log/ike.elg. The log shows 'Received notification from peer: NO_PROPOSAL_CHOSEN'. Which action should the administrator take next?

⚠ Common exam trap

The trap here is assuming that a Phase 2 failure means Phase 1 settings are wrong, when in fact Phase 1 already succeeded and the mismatch is in the IPsec proposal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Compare the Phase 2 encryption, hash, and Perfect Forward Secrecy settings on both peers and align them.

The NO_PROPOSAL_CHOSEN notification received during Phase 2 indicates the responder rejected the initiator's IPsec proposal because no matching proposal was found. The administrator should compare and align Phase 2 encryption, hash, and PFS settings on both peers. Phase 1 settings are already proven correct because Phase 1 completed, so the issue lies in the Quick Mode proposal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Compare the Phase 2 encryption, hash, and Perfect Forward Secrecy settings on both peers and align them.

    Why this is correct

    NO_PROPOSAL_CHOSEN during Phase 2 means the responder could not find an IPsec proposal matching the initiator's offer. The most common cause is a mismatch in Phase 2 encryption, hash, or PFS/DH group settings between the two gateways. Aligning these parameters on both peers allows the responder to select a matching proposal and complete Quick Mode, restoring the tunnel.

  • ✗

    Disable Perfect Forward Secrecy on the initiator only.

    Why it's wrong here

    Disabling PFS on only one peer creates an asymmetry: one side includes a DH group in the Phase 2 proposal while the other expects none, which can cause NO_PROPOSAL_CHOSEN. PFS must be consistent on both peers. The administrator should compare and align the full Phase 2 proposal on both sides, not unilaterally disable PFS on the initiator.

  • ✗

    Verify that the Phase 1 encryption and hash algorithms match on both peers.

    Why it's wrong here

    Phase 1 already completed successfully, which proves the Phase 1 encryption, hash, authentication, and DH group are compatible. Changing Phase 1 settings would not resolve a Phase 2 negotiation failure and could break the working Phase 1. The NO_PROPOSAL_CHOSEN notification in Phase 2 points specifically at the IPsec proposal, not the IKE proposal, so the administrator should focus on Phase 2 encryption, hash, and PFS settings instead.

  • ✗

    Increase the IKE Phase 1 renegotiation lifetime on both gateways.

    Why it's wrong here

    Phase 1 renegotiation lifetime affects when the IKE SA is refreshed, not whether Phase 2 proposals match. Since Phase 1 completed and Phase 2 failed with NO_PROPOSAL_CHOSEN, the problem is a mismatch in the IPsec proposal, not the lifetime value. Adjusting the lifetime would not resolve the Quick Mode failure and would leave the tunnel down.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 219 original CCSM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This CCSM practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSM exam.