After provisioning a Site-to-Site VPN between Contoso Azure VNet and an on-premises edge firewall, the connection status in the Azure portal shows 'NotConnected'. The on-premises firewall logs indicate an IKE_AUTH failure due to 'pre-shared key mismatch'. Which sequence of troubleshooting steps is most appropriate to resolve the problem?
Choose an answer
Tap an option to check your answer.
Correct answer: Verify the shared key (pre-shared key) configured on the Azure Connection resource matches the key configured on the on-premises device. Enable VPN diagnostic logs in Network Watcher, check IKE phase 1/2 details and the gateway diagnostic logs to confirm the mismatch and then reattempt connection..
Why this is the answer
The correct answer addresses the specific error message. An IKEAUTH failure due to 'pre-shared key mismatch' directly indicates that the pre-shared key (PSK) used for authentication during the IKE (Internet Key Exchange) phase 1 negotiation is not identical on both the Azure VPN gateway and the on-premises firewall. Therefore, verifying and correcting this key is the primary and most direct solution. Enabling diagnostic logs helps confirm the issue and provides further details for troubleshooting if the problem persists. Changing the Azure VPN Gateway SKU is irrelevant to a PSK mismatch; SKUs relate to performance and features, not authentication keys. Disabling BGP is incorrect because BGP is for routing, not authentication, and it does not automatically switch to certificates or eliminate the need for a PSK in a Site-to-Site VPN. Replacing with a Point-to-Site VPN is a different connectivity solution entirely and does not resolve the existing Site-to-Site PSK mismatch.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed