IKE Parameters That Must Match for IPsec Tunnel Establishment
Which THREE factors must match between two IKE peers for successful IPsec tunnel establishment? (Choose three.)
Quick Answer
The correct answer, IKE version, matters because IKE peers negotiate a security association before any encrypted traffic can flow, and that negotiation only succeeds if both sides are speaking the same protocol dialect from the very first exchange. IKEv1 and IKEv2 are not interchangeable or backward compatible mid-negotiation, so if one peer is configured for one version and the other for the different version, the initial handshake fails before any other parameter even gets compared. Beyond the version itself, the peers also need to agree on the specific cryptographic parameters proposed for that negotiation, such as the encryption algorithm used to protect the phase 1 exchange; if the proposed algorithms don't overlap between the two sides, the peers can't agree on how to secure their communication even if they're both running the same IKE version. Both of these are mandatory matching parameters precisely because IKE is a negotiation protocol, not a one-sided configuration, so every parameter that affects how the two sides interpret and protect their exchange has to have at least one mutually acceptable option on both ends. When a question asks what must match between IKE peers, think in terms of protocol version and the cryptographic proposal parameters, since any mismatch there prevents the SA from ever being established.
⚠ Common exam trap
It's easy for candidates to confuse 'factors that must match' with 'factors that can be different'—DPD intervals and certificate requirements are not mandatory for tunnel establishment, while IKE version, encryption, and authentication algorithms are non-negotiable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IKE encryption algorithm
Option B (IKE encryption algorithm) is correct because both peers must agree on the same Phase 1 encryption algorithm (e.g., AES-256) in their IKE proposals; a mismatch causes the ISAKMP/IKE SA negotiation to fail. Option C (IKE authentication algorithm) is correct because the Phase 1 integrity/hash algorithm (e.g., SHA-256) must match on both peers for the IKE SA to be established. Option E (IKE version v1 or v2) is correct because IKEv1 and IKEv2 are incompatible protocols; peers must run the same version to negotiate the tunnel. Option A (dead peer detection interval) is not required to match, since DPD timers are locally significant and can differ between peers without preventing tunnel establishment. Option D (local certificate) is not required to match, because each peer presents its own identity credential; certificates need only be trusted/validated, not identical.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dead peer detection interval
Why it's wrong here
Dead peer detection intervals are configured independently on each peer and are not negotiated, so mismatched values still permit tunnel establishment. DPD timing matters for detecting failures, not for bringing the tunnel up; it would be the answer if the question asked about liveness detection.
- ✓
IKE encryption algorithm
Why this is correct
IKE encryption algorithm must match because it secures Phase 1 negotiation itself; mismatched ciphers cause the peers to reject each other's proposals before any tunnel forms. This satisfies the stem's requirement that both peers agree on identical Phase 1 parameters for successful IPsec establishment.
- ✓
IKE authentication algorithm
Why this is correct
The IKE authentication algorithm must match because it secures the peer authentication exchange itself, distinct from the IPsec data-plane algorithms. Mismatched hashes (for example SHA-256 versus SHA-1) cause the IKE SA proposal to fail, so no tunnel forms. This satisfies the stem's requirement for matching IKE peer parameters.
- ✗
Local certificate
Why it's wrong here
Certificates are per-peer identity credentials, not negotiated parameters; each peer validates the other's certificate against a trusted CA, so the certificates themselves differ. Matching local certificates would be required only when both peers must present identical credentials, such as in some pre-shared-key-free lab setups.
- ✓
IKE version (v1 or v2)
Why this is correct
IKE version must match because IKEv1 and IKEv2 use different header formats, exchange types and SA payload structures; a peer offering only IKEv2 cannot negotiate with an IKEv1-only peer, so phase 1 fails before any proposal is evaluated.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PCNSE
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. What is the most likely cause of Phase2 being down?
easy- A.Mismatched IKE version
- ✓ B.Mismatched IPSec encryption or authentication settings
- C.Wrong tunnel interface IP address
- D.Incorrect pre-shared key
Why B: Phase 2 of an IPsec VPN tunnel establishes the IPsec security associations (SAs) for encrypting and authenticating data traffic. If the Phase 2 parameters, such as encryption algorithm (e.g., AES-256 vs. AES-128), authentication algorithm (e.g., SHA-256 vs. SHA-1), or DH group (e.g., group 14 vs. group 2), do not match between peers, the IKEv2 or IKEv1 Quick Mode negotiation will fail, leaving Phase 2 down. This is the most common cause of a successful Phase 1 (IKE SA) but a failed Phase 2.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.