Request for step-by-step configuration + screenshots for NO_PROPOSAL_CHOSEN (MX85 → MX64)

Solved
palakshah
Just browsing

Request for step-by-step configuration + screenshots for NO_PROPOSAL_CHOSEN (MX85 → MX64)

NO_PROPOSAL_CHOSEN error — I’m not fully confident interpreting it and would like step-by-step guidance to get a secure IPSec tunnel working between our devices.

My topology: Hub / starting point = MX85 → Spoke / ending point = MX64.

Main Requirement :- IPsec Tunnel  Between  mx85  to  mx64    --very secure tunnel  with full  control   to send and receive  data between  two mx devices

Could you please provide a clear, easy-to-follow configuration guide (with screenshots) that includes:

  1. Exact UI steps and screenshots for the pages/fields to set on both MX85 and MX64 (menu path + fields to fill).
  2. Recommended Phase 1 (IKE) parameters (exact values you want me to enter):
    • IKE version (v1 / v2)
    • Encryption algorithm(s)
    • Hash / integrity algorithm(s)
    • DH group
    • Lifetime (seconds)
    • Mode (Main / Aggressive) and NAT traversal settings
  3. Recommended Phase 2 (IPSec) parameters (exact values):
    • Encryption / integrity algorithms
    • PFS (on/off and DH group)
    • Lifetime (seconds)
  4. Exact format/requirements for the pre-shared key (length/characters) and any best practices for generating it.
  5. Any Meraki-specific requirements (for MX→MX vs. Meraki→non-Meraki peers) that I should be aware of.
  6. NAT, firewall, or port-forwarding considerations that commonly cause NO_PROPOSAL_CHOSEN.
  7. A short verification checklist or UI checks I can run after configuring each side to confirm proposals match.
  8. Examples or annotated screenshots of the VPN log entries you want me to capture if the problem continues — please show the exact log lines to capture.
  9. If possible, a “copy-paste” example of Phase 1/Phase 2 proposals that will work for MX85↔MX64 to avoid negotiation mismatch.
1 Accepted Solution
RWelch
Kind of a big deal
Kind of a big deal

Are both MX in the same organization (S2S VPN)?  Or are you trying to use NMVPN?

Site-to-Site VPN Settings 

Meraki Auto VPN - Configuration and Troubleshooting 

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.

View solution in original post

4 Replies 4
RWelch
Kind of a big deal
Kind of a big deal

Are both MX in the same organization (S2S VPN)?  Or are you trying to use NMVPN?

Site-to-Site VPN Settings 

Meraki Auto VPN - Configuration and Troubleshooting 

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
palakshah
Just browsing

Meraki Device --Mx 85 to    Mx 64

Non Meraki  IpSec  Tunnel

palakshah
Just browsing

both  are  different   different  --organization    --NMVPN  IS  MY  MAIN   POINT

palakshah
Just browsing


 please share best solution  &  documentation for "Configuring Site-to-site VPN between MX Appliances in Different Organizations".

Get notified when there are additional replies to this discussion.