Support Support Downloads Knowledge Base Case Manager My Juniper Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

Log Viewer: RECEIVED <<< ISAKMP OAK INFO *(HASH,NOTIFY:NO_PROPOSAL_CHOSEN)

0

0

Article ID: KB6234 KB Last Updated: 10 Jun 2010Version: 4.0
Summary:
Log Viewer: RECEIVED<<< ISAKMP OAK INFO *(HASH,NOTIFY:NO_PROPOSAL_CHOSEN)
Symptoms:

Environment:

  • IKE Phase 1 Negotiation successful

Symptoms & Errors:

  • Log Viewer: RECEIVED<<<ISAKMP OAK INFO *(HASH,NOTIFY:NO_PROPOSAL_CHOSEN)
  • Dial Up VPN is not working
  • Discarding IPSEC SA Negotiation
  • Rejected proposals from peer.  Negotiations have failed.
Solution:

This solution applies to NetScreen-Remote:

There are several possible reasons for the NO_PROPOSAL_CHOSEN message:

  1. Phase 2 Encrypt Alg. on NetScreen-Remote does not match the AutoKey IKE Phase 2 Proposal on the NetScreen
  2. Phase 2 Hash Alg. on NetScreen-Remote does not match the AutoKey IKE Phase 2 Proposal on the NetScreen
  3. Perfect Forward Secrecy is enabled on NetScreen-Remote, but NOPFS is configured on the NetScreen
  4. Perfect Forward Secrecy is not enabled on NetScreen-Remote, but PFS g2 is configured on the NetScreen 
Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search