An IPSec VPN tunnel configured on an NSX Gateway fails to establish or drops unexpectedly.
The IKE Phase 1 negotiation succeeds and shows as Up, but the Phase 2 (IPSec SA) status remains Down.
When executing get ipsecvpn session status via the NSX CLI on the Edge node, Phase 2 negotiations fail with an explicit cryptographic proposal error."No proposal chosen. DH Group Mismatch. Peer proposes: NONE"
VMware NSX
The tunnel failure is caused by a cryptographic profile mismatch during the Phase 2 negotiation.
Specifically, the Perfect Forward Secrecy (PFS) configuration does not match between the endpoints.
The NSX IPSec profile enforces PFS with a specific Diffie-Hellman (DH) group requirement, whereas the remote third-party peer has PFS entirely deactivated (NONE).
Because NSX cannot find a common cryptographic proposal with the peer for Phase 2, the security association (SA) generation is rejected.
This is a condition that may occur in a VMware NSX environment when security parameters between NSX and third-party endpoints are misaligned.
To resolve the mismatch, the security parameters must match on both sides. If you do not have administrative access to the remote peer to activate PFS, you must align the NSX configuration to accept the peer's proposal:
Log in to the NSX Manager UI.
Navigate to Networking > VPN > IPSec Sessions.
Edit the affected IPSec Session and locate the assigned IPSec Profile (which dictates Phase 2 parameters).
If the session is using a system-default profile, create a custom profile clone.
Edit the custom IPSec profile and Disable Perfect Forward Secrecy (PFS) / set the DH Group to NONE.
Save the profile changes and apply it to the IPSec session.
The tunnel will immediately renegotiate Phase 2 parameters and should establish successfully.
If you are contacting Broadcom support about this issue, please provide the following:
NSX Manager support bundles.
NSX Edge support bundles from the active Edge nodes hosting the gateway.
Handling Log Bundles for offline review with Broadcom support: