Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 156-215.80 All Questions

View all questions & answers for the 156-215.80 exam

Exam 156-215.80 topic 1 question 91 discussion

Actual exam question from Checkpoint's 156-215.80
Question #: 91
Topic #: 1
[All 156-215.80 Questions]

When attempting to start a VPN tunnel, in the logs the error 'no proposal chosen' is seen numerous times. No other VPN-related log entries are present. Which phase of the VPN negotiations has failed?

  • A. IKE Phase 1
  • B. IPSEC Phase 2
  • C. IPSEC Phase 1
  • D. IKE Phase 2
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
oluchecpoint
Highly Voted 4 years, 11 months ago
A See the url below https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk157494&t=1574714200294
upvoted 12 times
...
mauchi
Highly Voted 3 years, 10 months ago
I think the key here is the "no other VPN related logs are present" part. That makes me think that they are just beginning to set up IKE, therefore it's failing in Phase 1
upvoted 5 times
...
lukealba
Most Recent 2 years, 1 month ago
In Phase 1 there is IKE SA, in Phase 2 IPSEC SA. CCSE R81.10 Manual pages 373-374
upvoted 3 times
...
RCL_NAME
2 years, 11 months ago
D is the answer : https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114834
upvoted 1 times
...
dml90
3 years, 8 months ago
Seems like A is correct https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk157494
upvoted 4 times
...
lennie1
3 years, 9 months ago
http://help.stonesoft.com/onlinehelp/StoneGate/SMC/5.3.5/SGAG/SG_FWIPS_LogFieldValues/VPN_Errors.htm
upvoted 1 times
...
Sithudamo
3 years, 11 months ago
Anwser is IKE Phase 2
upvoted 1 times
babajana
3 years, 11 months ago
please explain
upvoted 1 times
...
...
FC49
5 years, 1 month ago
Looks like Phase 2 https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/11810/FILE/How-To-Troubleshoot-VPN-issues-with-Endpoint-Connect.pdf https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk88780 Summary: Phase-two Quick Mode failure occurs due to configuration/misconfiguration of VPN/encryption domain for firewalls involved in Site-to-Site VPN tunnels. Typically, this occurs when VPN domain group contains either numerous networks, or numerous hosts from different consecutive networks along with network objects. This article discusses troubleshooting the supernetting issue. https://community.cisco.com/t5/vpn-and-anyconnect/vpn-problem-between-cisco-and-check-point/td-p/469149 Quick mode only phase 2? FW errors: IKE: Main Mode Received Notification from Peer: Initial Contact IKE: Main Mode completion. IKE: Quick Mode Received Notification from Peer: no proposal chosen IKE: Quick Mode Received Notification from Peer: no proposal chosen
upvoted 1 times
...
emre_t
5 years, 2 months ago
Shouldn't A be the answer ? https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk157494
upvoted 2 times
Hernan_Mella
2 years, 4 months ago
Symptoms I think too: Tunnel is down between Check Point Gateways with "No Proposal chosen," fails in phase 1 packet 1 or packet 2 (Main mode).
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...