Courseiva
Authentication and VPNmediumMultiple ChoiceObjective-mapped

NSE4 Authentication and VPN Practice Question

A network admin configures an IPsec VPN between two FortiGates using IKEv2. Phase 1 completes successfully, but Phase 2 fails to establish. The admin runs 'diagnose vpn ike log' and sees the error 'proposal mismatch'. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates confuse 'proposal mismatch' with Phase 1 issues or selector mismatches, but the error is specific to cryptographic algorithm negotiation in Phase 2, not to network-layer subnet definitions or authentication credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The Phase 2 encryption and authentication algorithms do not match

The error 'proposal mismatch' in the 'diagnose vpn ike log' output specifically indicates that the Phase 2 parameters (encryption, authentication, or DH group) do not match between the two FortiGate peers. Since Phase 1 completed successfully, the IKE version (IKEv2) and pre-shared keys are already validated, leaving only the Phase 2 proposal as the cause. Option C correctly identifies that the encryption and authentication algorithms are mismatched, which is the most common reason for this error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The IKE version is not compatible

    Why it's wrong here

    The IKE version is not the culprit here because both FortiGates are explicitly configured to use IKEv2, and IKE version negotiation occurs during Phase 1. If the versions were incompatible, the Phase 1 IKE SA would never be established, preventing any Phase 2 negotiation from starting. The presence of a 'proposal mismatch' error during Phase 2 categorically proves that Phase 1 completed successfully, including all IKE version and SA exchanges. Thus, an IKE version mismatch is not a plausible cause for this specific Phase 2 error.

  • The Phase 2 selectors (local and remote subnets) are misconfigured

    Why it's wrong here

    While incorrect local and remote Phase 2 selectors (proxy IDs) can prevent a tunnel from carrying traffic, they do not cause a 'proposal mismatch' error in FortiGate's logs. A selector mismatch typically results in 'no proposal chosen' or a failure to negotiate the IPsec SA because the traffic selectors do not match, or the tunnel may come up but fail to encrypt the expected subnets. The 'proposal mismatch' notification specifically indicates that the cryptographic transform sets (encryption, authentication, PFS) offered by the initiator were rejected by the responder, not that the protected subnets were different.

  • The Phase 2 encryption and authentication algorithms do not match

    Why this is correct

    The correct interpretation of the 'proposal mismatch' error is that the Phase 2 encryption and authentication algorithms, or other transform parameters like the PFS Diffie-Hellman group, differ between the two FortiGates. During IKE Phase 2, the initiator sends a list of SA proposals containing encryption algorithms (e.g., AES128/256), integrity algorithms (e.g., SHA1/256), and optionally DH groups for PFS. If none of the responder's configured Phase 2 proposals match any of the initiator's proposals, the responder sends the 'no proposal chosen' or 'proposal mismatch' notification. To resolve this, the Phase 2 transform sets (encryption, authentication, and PFS) must be aligned on both endpoints.

  • The pre-shared keys do not match

    Why it's wrong here

    Pre-shared keys are used for authenticating the peer during Phase 1, not Phase 2. If the pre-shared keys did not match, the IKE Phase 1 authentication would fail, generating a different error such as 'pre-shared key mismatched' or 'authentication failed' and preventing the establishment of the IKE SA. A Phase 2 'proposal mismatch' error can only occur after Phase 1 has been successfully established with a valid PSK, so mismatched keys are definitively not the cause. Additionally, PSK mismatch affects the integrity of the entire IKE SA, whereas 'proposal mismatch' is a negotiation error between cryptographic algorithms, which is phase-specific.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE4 question from scratch — 282 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.