Häufig gestellte Fragen
My connection request in VPN Tracker is rejected with "No Proposal Chosen". What can I do?
This message in VPN Tracker means that the VPN gateway isn't willing to accept any of the proposals that VPN Tracker has offered.
As the proposals have not changed since the last successful connect (VPN Tracker always keeps record of the last successful settings, so we were able to compare your current settings to them), somebody must have changed the settings on the gateway side and now your client settings don't match any longer.
No proposal chosen means that your VPN gateway could not agree to any of the Phase 1 proposals that VPN Tracker sent to it. Phase 1 proposals include:
- Exchange mode (main/aggressive)
- Encryption (3DES, AES-128, etc.)
- Hashing (SHA-1, SHA-256, etc.)
- Diffie-Hellman Group (Group 2, Group 5, etc.)
Please double check which values are currently set on the VPN gateway. You need to offer at least the same values in VPN Tracker for Phase 1.
Also please double check your local identifier in VPN Tracker. If a VPN gateway supports multiple VPN tunnels and your client settings are correct for tunnel A, however the gateway thinks you want to connect to tunnel B, then this can also explain a configuration mismatch. With aggressive mode connection, the local identifier in VPN Tracker is used to select a remote tunnel, so in case there are multiple remote tunnels, please ensure you are targeting the correct one at the moment. The local identifier in VPN Tracker must match the tunnel name or remote identifier on the VPN gateway (remote as local and remote swap roles on the gateway side - for the gateway you are remote).