Proposal mismatch

Symptom

The proposals mismatch.

Analysis

The following is the debugging information:

got NOTIFY of type NO_PROPOSAL_CHOSEN

Or

drop message from A.B.C.D due to notification type NO_PROPOSAL_CHOSEN

The two parties in the negotiation have no matched proposals.

Solution

For the negotiation in phase 1, check that IKE proposals on both ends have a match. For the negotiation in phase 2, check that the IPsec policy settings match on both ends, and that the referenced IPsec transform sets on both ends have a match in protocol, encryption and authentication algorithms.