HA VPN tunnels fail to establish with logs showing: "received NO_PROPOSAL_CHOSEN notify, no CHILD_SA built" and Cloud Console shows "Negotiation failure" and "BGP is down". You control both cloud and on‑prem VPN devices. What corrective action should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Compare and review the Phase 2 (IKE CHILD_SA) settings on the on‑prem firewall and ensure they match one of the HA VPN supported cipher suites..
Why this is the answer
The error message "received NOPROPOSALCHOSEN notify, no CHILDSA built" specifically indicates a failure in Phase 2 (CHILDSA) negotiation. This means the IKEv2 parameters for establishing the IPsec tunnel itself, such as encryption algorithms, authentication algorithms, and Perfect Forward Secrecy (PFS) groups, do not match between the Google Cloud HA VPN gateway and the on-premises device. Reviewing and correcting these Phase 2 settings on the on-premises firewall to align with Google Cloud's supported cipher suites is the direct solution. Updating the BGP session configuration (first incorrect option) is irrelevant to the "NOPROPOSALCHOSEN" error, which occurs before BGP can even establish. Creating a new Cloud VPN gateway in a different region (third incorrect option) would not resolve a configuration mismatch. Recreating the tunnel with different IKE version and pre-shared key (fourth incorrect option) addresses Phase 1 issues, but the error explicitly points to Phase 2.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed