Courseiva
Authentication and VPN →mediumMultiple Choice

IPsec VPN No Proposal Chosen: Phase 1 Mismatch Causes

A FortiGate admin is troubleshooting an IPsec VPN tunnel that fails to establish. The remote site uses aggressive mode. The local FortiGate is configured for main mode. The admin sees 'no proposal chosen' in the IKE debug. What is the MOST likely cause?

⚠ Common exam trap

The trap here is that candidates often associate 'no proposal chosen' only with encryption or authentication algorithm mismatches, overlooking that IKE mode mismatch is also a proposal-level failure that triggers the same error in IKE debug.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IKE mode (main vs aggressive) does not match between peers

The 'no proposal chosen' error in IKE debug indicates a mismatch in the IKE parameters proposed by the peers. Since the remote site uses aggressive mode and the local FortiGate is configured for main mode, the IKE mode mismatch prevents the peers from agreeing on a proposal. IKE main mode and aggressive mode use different packet formats and exchange sequences, so they cannot negotiate a common proposal even if all other parameters match.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The pre-shared key is incorrect

    Why it's wrong here

    The pre-shared key is only used in the final authentication messages of IKE Phase 1, not during the initial SA proposal exchange. If the PSK were incorrect, the peers would successfully agree on a proposal and then fail the authentication hash, producing an INVALID_COOKIE or AUTHENTICATION_FAILED notify instead. 'No proposal chosen' is generated when the responder rejects the proposal itself, which happens before authentication is ever attempted.

  • ✓

    The IKE mode (main vs aggressive) does not match between peers

    Why this is correct

    Main mode and Aggressive mode differ in the number of IKE messages and whether the SA proposal is sent in the first packet with the same structure. When one peer is set to Main mode and the other to Aggressive mode, the responder sees a proposal that does not match the expected exchange type and therefore rejects it with a NO_PROPOSAL_CHOSEN notify, because the transforms are not considered valid for the configured mode. This is one of the classic causes of this exact error on FortiGate.

  • ✗

    The local firewall is blocking UDP port 500

    Why it's wrong here

    If a firewall were blocking UDP port 500, the initial IKE packets would never reach the remote peer, so no negotiation would occur at all. The initiator would retransmit and eventually time out without ever receiving a protocol response. The 'no proposal chosen' error is a specific IKE notify payload that can only be sent by a peer that has actually received and processed the SA proposal, which proves UDP 500 connectivity exists.

  • ✗

    The Phase 2 encryption algorithm is not supported

    Why it's wrong here

    The 'no proposal chosen' error is inherently a Phase 1 failure: it is the responder's rejection of the IKE SA proposal that includes encryption, hash, DH group, and authentication method for the IKE tunnel. Phase 2 encryption algorithms are negotiated only after Phase 1 is successfully established, so a Phase 2 mismatch would produce a later failure like a Quick Mode timeout or authentication error, not a Phase 1 notify. Thus this option incorrectly assigns a Phase 2 attribute to a Phase 1 negotiation problem.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.