MX Security Audit Failed - Recommended Steps
Overview
This document provides recommended steps to address Cisco Meraki MX WAN appliance security audit failures. The document covers two common scenarios that trigger security audit failures on MX devices:
- Detection of aggressive mode Internet Key Exchange (IKE)
- Flagged Client VPN encryption or Diffie-Hellman (DH) group settings
Troubleshooting security audit failure due to aggressive mode IKE
Prior to the release of the MX 15 firmware branch, Cisco Meraki MX Client VPN supported the use of Aggressive Mode IKE with Pre-Shared Key (PSK) authentication. You may occasionally encounter issues during security audits or vulnerability scans where security scans detect Aggressive Mode IKE. However, Cisco Meraki no longer supports this and has not been since MX 15 was released.
Why Does This Flag Occur?
Scans typically flag this because MX devices still respond to such requests, but do so by sending a NO-PROPOSAL-CHOSEN notification message, the standard way of indicating that the request has been rejected. There is no way for Meraki Support to modify this behavior, and any findings from security scans under this circumstance should be treated as false positives.
Troubleshooting steps
- Confirm that the MX device runs MX 15 firmware or later. MX devices running MX 15 or later do not support aggressive mode IKE.
- Confirm that the MX device responds to aggressive mode IKE requests only by sending a NO-PROPOSAL-CHOSEN notification message; the standard indication that the request has been rejected.
- Treat scan findings under this circumstance as false positives. Meraki Support cannot modify this behavior.
- Share RFC 2408 Section 5.4 with your security audit team for further technical details if needed.
Troubleshooting security audit failure due to client VPN encryption
Security audits may flag the encryption or DH groups used by legacy L2TP/IPsec Client VPN. These settings are part of the legacy Client VPN implementation.
Troubleshooting steps
If stronger encryption or modern IKE negotiation is required, migrate to IKEv2 Client VPN, which is available on MX firmware 26.1.X and later. see Client VPN Overview.

