- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-23-2026 03:43 AM
After upgrading to panos preffered version 12.1.7-h3 my ikev1 ipsec tunnel with ipsec crypto md5,3des,nopfs is not coming up , knowing that ike phase 1 is successful but ike phase 2 is giving no proposal chosen error , the algorithms matches the other peer and i tried downgrading the tunnel came up, i would appreciate any help
08-24-2026 04:08 AM
Is there a reason you're using these deprecated protocols?
Unless your peer device is something ancient, it would be better to switch to modern crypto profiles and see if that not automatically fixes your issue
08-24-2026 04:19 AM
We are forced to use these old algorithms as the peer seems like a very old device. cisco i believe.
08-24-2026 04:38 AM
that is very unfortunate!
I've heard of this issue before on PAN-OS 12, maybe a bug or a QA oversight due to the sheer age of these protocols. You could open up a support case to have that investigated, but i would recommend trying to upgrade the crypto profile.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

