Courseiva
Authentication and VPN →mediumMultiple Choice

NSE4 Authentication and VPN Practice Question

The output of 'diagnose debug application ike -1' shows 'no proposal chosen' for a Phase1 negotiation. Which action should the administrator take to resolve this?

⚠ Common exam trap

A common mix-up: candidates confuse 'no proposal chosen' with authentication failures (pre-shared key mismatch) or version incompatibility, but the error specifically occurs during the proposal exchange before authentication or version negotiation takes place.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check and align the Phase1 encryption, authentication, and DH group settings

The 'no proposal chosen' error in Phase 1 IKE negotiation indicates that the two VPN peers cannot agree on a common set of security parameters (proposal). The administrator must check and align the Phase 1 settings, specifically the encryption algorithm, authentication method, and Diffie-Hellman group, because these are the mandatory parameters matched during the IKE SA negotiation. Option C directly addresses this by ensuring both sides use identical Phase 1 proposals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the Phase1 lifetime on both sides

    Why it's wrong here

    Adjusting the Phase1 lifetime cannot resolve a 'no proposal chosen' error because lifetime is not part of the SA transform set used to match proposals. IKE peers negotiate lifetime after agreeing on encryption, authentication, and DH group parameters, and a mismatch simply results in the shorter lifetime being used. If no common proposal exists, the negotiation fails before lifetime is ever considered, so changing it has no effect on this error.

  • ✗

    Verify the pre-shared key is correct

    Why it's wrong here

    Verifying the pre-shared key is not the right fix because PSK validation occurs only after both peers have successfully matched a Phase1 proposal. A wrong pre-shared key causes an authentication failure, typically reported as 'authentication failed' or INVALID_PAYLOAD, not 'no proposal chosen'. The pre-shared key is not an attribute of the IKE proposal itself, so it is irrelevant to the proposal-matching stage where this error originates.

  • ✓

    Check and align the Phase1 encryption, authentication, and DH group settings

    Why this is correct

    This is the correct action: 'no proposal chosen' is an IKE Phase1 notification sent by the responder when it cannot find any overlap between its configured Phase1 parameters and the initiator's proposed transforms. The encryption algorithm, authentication/integrity algorithm, and Diffie-Hellman (DH) group must all match on both peers, and if any one of them differs, the proposal is rejected. Checking and aligning these settings directly addresses the root cause and is the standard troubleshooting step for this error.

  • ✗

    Change the IKE version from v1 to v2

    Why it's wrong here

    Changing the IKE version from v1 to v2 will not fix this issue because the error stems from a mismatch in transform parameters, not from a protocol version mismatch. If the peers were using different IKE versions, negotiation would fail with a different error such as 'no acceptable proposal' or the packets would be silently dropped. Additionally, switching to v2 only works if both peers are configured to use v2, and even then, the underlying encryption, authentication, and DH group settings would still need to match.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.