Courseiva
Secure Access and VPN →hardMultiple Select

IKE Parameters That Must Match for IPsec Tunnel Establishment

Which THREE factors must match between two IKE peers for successful IPsec tunnel establishment? (Choose three.)

Quick Answer

The correct answer, IKE version, matters because IKE peers negotiate a security association before any encrypted traffic can flow, and that negotiation only succeeds if both sides are speaking the same protocol dialect from the very first exchange. IKEv1 and IKEv2 are not interchangeable or backward compatible mid-negotiation, so if one peer is configured for one version and the other for the different version, the initial handshake fails before any other parameter even gets compared. Beyond the version itself, the peers also need to agree on the specific cryptographic parameters proposed for that negotiation, such as the encryption algorithm used to protect the phase 1 exchange; if the proposed algorithms don't overlap between the two sides, the peers can't agree on how to secure their communication even if they're both running the same IKE version. Both of these are mandatory matching parameters precisely because IKE is a negotiation protocol, not a one-sided configuration, so every parameter that affects how the two sides interpret and protect their exchange has to have at least one mutually acceptable option on both ends. When a question asks what must match between IKE peers, think in terms of protocol version and the cryptographic proposal parameters, since any mismatch there prevents the SA from ever being established.

⚠ Common exam trap

It's easy for candidates to confuse 'factors that must match' with 'factors that can be different'—DPD intervals and certificate requirements are not mandatory for tunnel establishment, while IKE version, encryption, and authentication algorithms are non-negotiable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IKE encryption algorithm

Option B (IKE encryption algorithm) is correct because both peers must agree on the same Phase 1 encryption algorithm (e.g., AES-256) in their IKE proposals; a mismatch causes the ISAKMP/IKE SA negotiation to fail. Option C (IKE authentication algorithm) is correct because the Phase 1 integrity/hash algorithm (e.g., SHA-256) must match on both peers for the IKE SA to be established. Option E (IKE version v1 or v2) is correct because IKEv1 and IKEv2 are incompatible protocols; peers must run the same version to negotiate the tunnel. Option A (dead peer detection interval) is not required to match, since DPD timers are locally significant and can differ between peers without preventing tunnel establishment. Option D (local certificate) is not required to match, because each peer presents its own identity credential; certificates need only be trusted/validated, not identical.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dead peer detection interval

    Why it's wrong here

    Dead peer detection intervals are configured independently on each peer and are not negotiated, so mismatched values still permit tunnel establishment. DPD timing matters for detecting failures, not for bringing the tunnel up; it would be the answer if the question asked about liveness detection.

  • ✓

    IKE encryption algorithm

    Why this is correct

    IKE encryption algorithm must match because it secures Phase 1 negotiation itself; mismatched ciphers cause the peers to reject each other's proposals before any tunnel forms. This satisfies the stem's requirement that both peers agree on identical Phase 1 parameters for successful IPsec establishment.

  • ✓

    IKE authentication algorithm

    Why this is correct

    The IKE authentication algorithm must match because it secures the peer authentication exchange itself, distinct from the IPsec data-plane algorithms. Mismatched hashes (for example SHA-256 versus SHA-1) cause the IKE SA proposal to fail, so no tunnel forms. This satisfies the stem's requirement for matching IKE peer parameters.

  • ✗

    Local certificate

    Why it's wrong here

    Certificates are per-peer identity credentials, not negotiated parameters; each peer validates the other's certificate against a trusted CA, so the certificates themselves differ. Matching local certificates would be required only when both peers must present identical credentials, such as in some pre-shared-key-free lab setups.

  • ✓

    IKE version (v1 or v2)

    Why this is correct

    IKE version must match because IKEv1 and IKEv2 use different header formats, exchange types and SA payload structures; a peer offering only IKEv2 cannot negotiate with an IKEv1-only peer, so phase 1 fails before any proposal is evaluated.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PCNSE

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. What is the most likely cause of Phase2 being down?

easy
  • A.Mismatched IKE version
  • ✓ B.Mismatched IPSec encryption or authentication settings
  • C.Wrong tunnel interface IP address
  • D.Incorrect pre-shared key

Why B: Phase 2 of an IPsec VPN tunnel establishes the IPsec security associations (SAs) for encrypting and authenticating data traffic. If the Phase 2 parameters, such as encryption algorithm (e.g., AES-256 vs. AES-128), authentication algorithm (e.g., SHA-256 vs. SHA-1), or DH group (e.g., group 14 vs. group 2), do not match between peers, the IKEv2 or IKEv1 Quick Mode negotiation will fail, leaving Phase 2 down. This is the most common cause of a successful Phase 1 (IKE SA) but a failed Phase 2.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.