← CCNP Security: SCOR core and operations
15 / 25 · 55 MIN

VPN: negotiation and traffic path

Distinguish IKE, Child SA and usable service, diagnosing each stage with scoped evidence.

1. Separate connection states

A fictional connection between a processing site and a partner supports closing reports. The dashboard shows established IKE, but the file never arrives. This is not contradictory: the IKE association supports negotiation and control, while Child SAs protect selected traffic. The RFC allows an IKE SA to exist when the first Child SA fails for reasons such as unacceptable selectors. Before changing parameters, record peer, identity, version, time, stage and outcome. Do not use “VPN up” as a synonym for delivered service. Acceptance also requires representative traffic, a return path, applicable policy and application confirmation of the result.

2. Interpret stage and error

The worksheet presents three independent clues. NO_PROPOSAL_CHOSEN during IKE_SA_INIT calls for comparing IKE proposals; the same error type during Child SA creation directs analysis to that proposal. TS_UNACCEPTABLE points to selector scope rather than proving a wrong password. AUTHENTICATION_FAILED calls for reviewing identity and authentication method without exposing the key in the ticket. For certificates, include validity, chain and observed clock. A shared proposal must remain within approved policy. Do not add old algorithms broadly to obtain any green connection. Retain stage and context because error text alone may not identify the component.

3. Follow protected traffic

In the worksheet, A protects 10.60.10.0/24 toward 10.70.20.0/24, but B accepts only source 10.60.10.0/25. Host.30 lies within both.200 is outside the half accepted by B. Reconcile that difference against authorized scope without widening everything to any source. Also consider NAT translation and effective rule order. A route-based VPN requires routing toward the VTI and suitable access policy; creating the interface does not magically create a working route. Compare counters before and after one scoped attempt on both peers. Encrypting without receiving a reply can have remote, return-path or application causes and does not itself establish a wrong key.

4. Validate change and continuity

Configuration saved in the manager may still await deployment. Confirm the effective revision and both ends before measuring results. On a backup VTI, the backup label alone does not select the path: routing participates in selection. Continuity testing should measure transactions, reconvergence and capacity after an authorized failure rather than only an SA reappearing. A periodic interruption calls for correlation with rekey, expiry, routing and both peers’ logs; convenient timing alone does not establish rekey. Define rollback conditions and a partner contact able to execute and confirm actions on the equipment they manage.

5. Hand useful diagnosis to RUN

Handover includes permitted flows, selectors, routes, identity, owners, alarms and evidence of positive and negative tests. Capture only what the investigation needs and treat credentials as secrets. Debugging can consume significant CPU; define window, scope, duration, stop criteria and confirmation that it was disabled. General event guidance recommends avoiding beginning/end duplication where possible, while the VPN diagnostic chapter requests both for its view. That difference calls for a contextual decision and volume control. The worksheet is a tabletop exercise without an executed Cisco tunnel. Summary: separate control, data and service, progressing through evidence that distinguishes the next hypothesis.

IN PRACTICE

Host 10.60.10.30 belongs to /25; 10.60.10.200 does not. Active IKE resolves neither selector differences nor report delivery.

Common pitfalls

IKE state as application acceptance; changing keys for every error; widening selectors without authorization; unlimited debug.

Related topics: IPsec and IKEv2 · Routing and NAT · Change management

Take this idea with you

VPN diagnosis needs stage, flow, direction and observed outcome.

Create account

Reference: Site-to-Site VPN · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security

CCNP® and Cisco® are registered trademarks of Cisco Systems, Inc. and/or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by Cisco. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.