When attempting to start a VPN tunnel, in the logs the error 'no proposal chosen' is seen numerous times. No other VPN-related log entries are present. Which phase of the VPN negotiations has failed?
I think the key here is the "no other VPN related logs are present" part. That makes me think that they are just beginning to set up IKE, therefore it's failing in Phase 1
Looks like Phase 2
https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/11810/FILE/How-To-Troubleshoot-VPN-issues-with-Endpoint-Connect.pdf
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk88780
Summary: Phase-two Quick Mode failure occurs due to configuration/misconfiguration of VPN/encryption domain for firewalls involved in Site-to-Site VPN tunnels. Typically, this occurs when VPN domain group contains either numerous networks, or numerous hosts from different consecutive networks along with network objects. This article discusses troubleshooting the supernetting issue.
https://community.cisco.com/t5/vpn-and-anyconnect/vpn-problem-between-cisco-and-check-point/td-p/469149
Quick mode only phase 2?
FW errors:
IKE: Main Mode Received Notification from Peer: Initial Contact
IKE: Main Mode completion.
IKE: Quick Mode Received Notification from Peer: no proposal chosen
IKE: Quick Mode Received Notification from Peer: no proposal chosen
Symptoms
I think too: Tunnel is down between Check Point Gateways with "No Proposal chosen," fails in phase 1 packet 1 or packet 2 (Main mode).
upvoted 1 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
oluchecpoint
Highly Voted 4 years, 11 months agomauchi
Highly Voted 3 years, 10 months agolukealba
Most Recent 2 years, 1 month agoRCL_NAME
2 years, 11 months agodml90
3 years, 8 months agolennie1
3 years, 9 months agoSithudamo
3 years, 11 months agobabajana
3 years, 11 months agoFC49
5 years, 1 month agoemre_t
5 years, 2 months agoHernan_Mella
2 years, 4 months ago