IPsec VPN No Proposal Chosen: Phase 1 Mismatch Causes
A FortiGate admin is troubleshooting an IPsec VPN tunnel that fails to establish. The remote site uses aggressive mode. The local FortiGate is configured for main mode. The admin sees 'no proposal chosen' in the IKE debug. What is the MOST likely cause?
⚠ Common exam trap
The trap here is that candidates often associate 'no proposal chosen' only with encryption or authentication algorithm mismatches, overlooking that IKE mode mismatch is also a proposal-level failure that triggers the same error in IKE debug.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IKE mode (main vs aggressive) does not match between peers
The 'no proposal chosen' error in IKE debug indicates a mismatch in the IKE parameters proposed by the peers. Since the remote site uses aggressive mode and the local FortiGate is configured for main mode, the IKE mode mismatch prevents the peers from agreeing on a proposal. IKE main mode and aggressive mode use different packet formats and exchange sequences, so they cannot negotiate a common proposal even if all other parameters match.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pre-shared key is incorrect
Why it's wrong here
The pre-shared key is only used in the final authentication messages of IKE Phase 1, not during the initial SA proposal exchange. If the PSK were incorrect, the peers would successfully agree on a proposal and then fail the authentication hash, producing an INVALID_COOKIE or AUTHENTICATION_FAILED notify instead. 'No proposal chosen' is generated when the responder rejects the proposal itself, which happens before authentication is ever attempted.
- ✓
The IKE mode (main vs aggressive) does not match between peers
Why this is correct
Main mode and Aggressive mode differ in the number of IKE messages and whether the SA proposal is sent in the first packet with the same structure. When one peer is set to Main mode and the other to Aggressive mode, the responder sees a proposal that does not match the expected exchange type and therefore rejects it with a NO_PROPOSAL_CHOSEN notify, because the transforms are not considered valid for the configured mode. This is one of the classic causes of this exact error on FortiGate.
- ✗
The local firewall is blocking UDP port 500
Why it's wrong here
If a firewall were blocking UDP port 500, the initial IKE packets would never reach the remote peer, so no negotiation would occur at all. The initiator would retransmit and eventually time out without ever receiving a protocol response. The 'no proposal chosen' error is a specific IKE notify payload that can only be sent by a peer that has actually received and processed the SA proposal, which proves UDP 500 connectivity exists.
- ✗
The Phase 2 encryption algorithm is not supported
Why it's wrong here
The 'no proposal chosen' error is inherently a Phase 1 failure: it is the responder's rejection of the IKE SA proposal that includes encryption, hash, DH group, and authentication method for the IKE tunnel. Phase 2 encryption algorithms are negotiated only after Phase 1 is successfully established, so a Phase 2 mismatch would produce a later failure like a Quick Mode timeout or authentication error, not a Phase 1 notify. Thus this option incorrectly assigns a Phase 2 attribute to a Phase 1 negotiation problem.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.