Skip to main content
pginete
Staff
Staff
January 20, 2026

Troubleshooting Tip: IPsec tunnels are down on FortiGate with FIPS enabled after the firmware upgrade to v7.6.3

  • January 20, 2026
  • 0 replies
  • 576 views

Description

This article describes how to fix the IPsec tunnels that are down on FortiGate with FIPS enabled after the firmware upgrade to v7.6.3.

Scope

FortiGate.

Solution

ipsec tunnel down 7.6.3.png

 

The following errors are seen on the IKE debug.

 

2026-01-20 05:45:00.856557 ike V=root:0:site1:934: generate DH public value request pending
2026-01-20 05:45:00.923568 ike V=root:0:site1:934: compute DH shared secret request pending


Change the IPsec VPN tunnel PSK secret to have at least 14 characters to fix the IPsec VPN tunnels that are down.

Starting on FortiOS v7.6.1 with FIPS enabled, the IPsec VPN PSK secret needs to be at least 14 characters. This also affects dialup IPsec tunnel.

How to change the PSK secret on an IPsec VPN tunnel via the CLI:

 

config vpn ipsec phase1-interface
	edit "VPN tunnel name" 
		set psksecret ****
	next
end


Starting from FortiOS v8.0.0, a PSK secret length less than 14 will not be accepted.

Lab-FGT (dialup) # set psksecret 123456
Minimum psksecret length in FIPS-CC is 14.
node_check_object fail! for psksecret 123456
value parse error before '123456'
Command fail. Return code -651

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!