Courseiva
Secure Access and VPNmediumMultiple ChoiceObjective-mapped

PCNSE Secure Access and VPN Practice Question

Exhibit

set network tunnel ipsec ipsec-tunnel VPN-Tunnel
 set tunnel-interface tunnel.1
 set proxy-id local 192.168.1.0/24
 set proxy-id remote 10.0.0.0/8
 set proxy-id protocol any
 set ike-gateway GW1
 set ipsec-crypto-profile AES256-SHA256
commit

Refer to the exhibit. A firewall administrator configures an IPSec tunnel. After committing, the tunnel never becomes active. What is the most likely reason?

⚠ Common exam trap

The PCNSE exam often tests the misconception that configuring a tunnel interface and crypto profile is sufficient for an IPSec tunnel. However, the IKE gateway is a mandatory prerequisite for Phase 1 negotiation; its absence is a frequent root cause of inactive tunnels on Palo Alto firewalls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The IKE gateway configuration is missing.

B is correct because an IPSec tunnel requires both an IKE gateway configuration and an IPSec crypto profile to establish Phase 1 and Phase 2 security associations. Without the IKE gateway, the firewall has no peer address, authentication method, or pre-shared key to initiate IKEv1/v2 exchanges, so the tunnel remains down. The exhibit likely shows a tunnel interface and crypto profile but omits the IKE gateway object, which is mandatory for tunnel activation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The tunnel interface is not in a zone.

    Why it's wrong here

    Incorrect. Tunnel interface zone assignment affects policies, not tunnel establishment.

  • The IKE gateway configuration is missing.

    Why this is correct

    Correct. Without a valid IKE gateway, the tunnel cannot establish.

  • The proxy-id protocol should be set to '0' for all.

    Why it's wrong here

    Incorrect. 'any' is a valid setting for protocol.

  • The crypto profile name is invalid.

    Why it's wrong here

    Incorrect. The profile name is valid, and missing profile would cause commit error.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.