Troubleshooting Tip: IPsec VPN Tunnel is not coming up between FortiGate and Palo Alto
| Description | This article describes troubleshooting steps when the IPsec tunnel Phase 1 and Phase 2 are up on FortiGate hosted in Microsoft Azure, but the tunnel is not established from the Palo Alto side. |
| Scope | FortiGate, Palo Alto. |
| Solution | Scenario:
It can be noticed that Phase 1 and Phase 2 show UP on FortiGate, and the same can be verified using the below CLI commands and VPN event logs.
diagnose vpn tunnel list name <phase1-name> diagnose vpn ike gateway list name <phase1-name>
However, Phase 1 is not established on the Palo Alto firewall. Palo Alto logs display the error message: 'received id_r <FortiGate Private IP> type ipaddr does not match peers id'.
Leave the Local ID field blank on the FortiGate, and the remote end only needs to make the changes
config vpn ipsec phase1-interfac
From the GUI:
The Local ID option in the GUI cannot be seen when the Tunnel is created from the Wizard. In such cases, use the 'Convert to Custom Tunnel' option.
Related article: Technical Tip: Configuring IPSec tunnel between FortiGate and Palo Alto |



