Query on DH group for IPSEC VPN

Showing results for 
Search instead for 
Did you mean: 

Query on DH group for IPSEC VPN

L4 Transporter
We are having issue in building an IPSEC tunnel on a Palo firewall. Using ver 9.1.2.
Getting below error
'IKE phase-1 negotiation is failed. Couldn't find configuration for IKE phase-1 request for peer IP...
The peer IP type is Dynamic with no proxy ID in use. We are using IKEv1, DPD is disabled, NAT-t is enabled, Phase1 & 2 are matching at both ends, Exchange modes are also matching. PA is enabled in passive mode.
We had to set DH Group to no-pfs under IPsec crypto profile.
When setting no-pfs value is there any other setting we need to set on palo side for the tunnel to work?

Cyber Elite
Cyber Elite


The phase 1 properties are not correct for both sides of the tunnel. The 'receiving' side of the VPN should provide more information as to why. However start with the basics and make sure your ike settings are identical on both devices.


Also check your logs to make sure you are not dropping any of the traffic (doesnt sound like it however).



Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!