> Source: [sk164840](https://support.checkpoint.com/results/sk/sk164840)

# sk164840 - Site-to-Site IPSec VPN with certificates does not work - one of VPN peers sends "Sent Notification to Peer: no proposal chosen" for IKE Phase 1

| Property | Value |
|----------|-------|
| Solution ID | sk164840 |
| Date Created | 2020-01-22 |
| Last Modified | 2022-05-08 |
| Technical Level | Advanced |

## Symptoms

- * Site-to-Site VPN using certificates does not work. One of VPN peers is sending "`Sent Notification to Peer: no proposal chosen`" for IKE Phase 1.

* The VPND debug on the Security Gateway that sends "`no proposal chosen`" shows (in the *$FWDIR/log/vpnd.elg* file):

  ```
  
  [tunnel] fwisakmp_get_keyholder_keytypes: state does not have a key holder
  [tunnel] proposalListFromIkeProps: transL->translst doesn't contain elements
  [tunnel] MMProcess1: ERROR: Cannot build a proposal for GW
  GetCommunityByID: community ID [XXX] : Community_Name
  [tunnel] extended_log_info_build_reason_from_list: list is empty
  ```

## Cause

Possible causes:

* The IPSec certificate on the Security Gateway is corrupted.
* A wrong certificate is configured in the Security Gateway object.
* VPN certificate has expired.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
