> Source: [sk157494](https://support.checkpoint.com/results/sk/sk157494)

# sk157494 - VPN tunnel between Check Point Gateways is down with "No Proposal chosen" error

| Property | Value |
|----------|-------|
| Solution ID | sk157494 |
| Date Created | 2019-07-11 |
| Last Modified | 2020-02-17 |
| Technical Level | Advanced |

## Symptoms

- * Tunnel is down between Check Point Gateways with "`No Proposal chosen`," fails in phase 1 packet 1 or packet 2 (Main mode).
* tcpdump shows that the traffic is going back and forth between Security Gateways for ISAKMP/phase1 port 500.
* The *ike.elg* file shows that the Security Gateway that initiated the tunnel sent packet 1 of Main Mode, and that the peer then responded with info packet "`NO-PROPOSAL-CHOSEN.`"
* The *vpnd.elg* file shows:
  * On the local site (the Security Gateway that initiated the tunnel): "`Received Notification from Peer: no proposal chosen.`"
  * On the peer site: The remote Sent Notification "`no proposal chosen`" and "`ERROR: Cannot choose a proposal for GW.`"

## Cause

The issue was caused by one of the following scenarios:

* Scenario 1: The encryption methods do not match on both sites (local and peer).
* Scenario 2: There is a duplicate object with the same IP address.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
