Support Support Downloads Knowledge Base Service Request Manager My Juniper Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

Unable to Create Multiple Proposals with Differing Diffie-Hellman Groups in IKE Phase 1 or Phase 2



Article ID: KB6698 KB Last Updated: 06 Aug 2010Version: 4.0
NS-Remote is configured with one Phase 1 and one Phase 2 proposal.  On the Juniper Firewall, Phase 1 is configured with multiple proposals.  The proposals include DH1 and DH2.  For example, pre-g1-des-sha and pre-g2-des-sha.  The VPN is failing to negotiate.
  • Diffie-Hellman (DH)
  • IKE Phase 1 or Phase 2
  • Custom Proposal
  • Differing DH groups

Symptoms & Errors:

  • Error Message:  Mismatched DH group in the Phase 2 Proposals. The DH group must be identical in all proposals of a VPN Configuration. Please try again. 

  • VPN fails to negotiate past Phase 1.  On the Firewall, the debug ike detail shows:

    ## 2006-12-04 20:56:13 : IKE<> mismatched group for phase 1 aggressive mode.
    ## 2006-12-04 20:56:13 : IKE<> cannot convert proposals from peer (IKE Gate)

Configuration Example:

  1. Create custom p1 proposal pre-g5-3des-md5
  2. Create custom p2 proposal g5-esp-3des-md5
  3. Create Ike gateway, select two proposals from the drop menus: pre-g2-3des-md5 and pre-g5-3des-md5
  4. Create an AutokeyIKE VPN, using PFS, and selecting from the drop menus: g2-esp-3des-md5 and g5-esp-3des-md5, after clicking Return and OK you will received the following error message:
"Mismatched DH group in the Phase 2 Proposals. The DH group must be identical in all proposals of a VPN Configuration. Please try again."
When configuring either Phase 1 or Phase 2, the same DH group must be selected:

  • Due to protocol limitations, multiple proposals with differing Diffie-Hellman groups in IKE Phase 2 is not supported.   The error message is generated as expected.

  • When configuring multiple proposals for Phase 1, you have to use the same Diffie-Helman group in all proposals.  Using different Diffie-Helman groups will result in a failure in the IKE negotiation.

    For example, assume the peer is configured for pre-g2-des-sha.  The following configuration will fail:

    However, the following configuration will succeed:
Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Security Alerts and Vulnerabilities

Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search