NSE4 Authentication and VPN Practice Question
The output of 'diagnose debug application ike -1' shows 'no proposal chosen' for a Phase1 negotiation. Which action should the administrator take to resolve this?
⚠ Common exam trap
A common mix-up: candidates confuse 'no proposal chosen' with authentication failures (pre-shared key mismatch) or version incompatibility, but the error specifically occurs during the proposal exchange before authentication or version negotiation takes place.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check and align the Phase1 encryption, authentication, and DH group settings
The 'no proposal chosen' error in Phase 1 IKE negotiation indicates that the two VPN peers cannot agree on a common set of security parameters (proposal). The administrator must check and align the Phase 1 settings, specifically the encryption algorithm, authentication method, and Diffie-Hellman group, because these are the mandatory parameters matched during the IKE SA negotiation. Option C directly addresses this by ensuring both sides use identical Phase 1 proposals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the Phase1 lifetime on both sides
Why it's wrong here
Adjusting the Phase1 lifetime cannot resolve a 'no proposal chosen' error because lifetime is not part of the SA transform set used to match proposals. IKE peers negotiate lifetime after agreeing on encryption, authentication, and DH group parameters, and a mismatch simply results in the shorter lifetime being used. If no common proposal exists, the negotiation fails before lifetime is ever considered, so changing it has no effect on this error.
- ✗
Verify the pre-shared key is correct
Why it's wrong here
Verifying the pre-shared key is not the right fix because PSK validation occurs only after both peers have successfully matched a Phase1 proposal. A wrong pre-shared key causes an authentication failure, typically reported as 'authentication failed' or INVALID_PAYLOAD, not 'no proposal chosen'. The pre-shared key is not an attribute of the IKE proposal itself, so it is irrelevant to the proposal-matching stage where this error originates.
- ✓
Check and align the Phase1 encryption, authentication, and DH group settings
Why this is correct
This is the correct action: 'no proposal chosen' is an IKE Phase1 notification sent by the responder when it cannot find any overlap between its configured Phase1 parameters and the initiator's proposed transforms. The encryption algorithm, authentication/integrity algorithm, and Diffie-Hellman (DH) group must all match on both peers, and if any one of them differs, the proposal is rejected. Checking and aligning these settings directly addresses the root cause and is the standard troubleshooting step for this error.
- ✗
Change the IKE version from v1 to v2
Why it's wrong here
Changing the IKE version from v1 to v2 will not fix this issue because the error stems from a mismatch in transform parameters, not from a protocol version mismatch. If the peers were using different IKE versions, negotiation would fail with a different error such as 'no acceptable proposal' or the packets would be silently dropped. Additionally, switching to v2 only works if both peers are configured to use v2, and even then, the underlying encryption, authentication, and DH group settings would still need to match.
Visual reference
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.