Skip to main content
Alan_
Staff
Staff
July 3, 2026

Troubleshooting Tip: Possible resolution for 'IKE message other than DPD retransmits to maximum' error on FortiClient

  • July 3, 2026
  • 0 replies
  • 737 views

Description

This article describes how to resolve a possible issue where FortiClient is failing to establish a VPN connection due to an 'IKE message other than DPD retransmits to maximum' error.

Scope

FortiGate, FortiClient.

Solution

In a scenario where FortiClient must establish an IKEv2 VPN with authentication enabled, the client may report the following error message during the connection attempt: 'IKE message other than DPD retransmits to maximum'.

21b13e02.png


This behavior may occur because the user fails to provide credentials within the negotiation timeout period.

When debugging IKE on the FortiGate, logs similar to the following can be observed:

  • FortiGate successfully negotiates an SPI with the FortiClient during phase 1.

  • The 'in' and 'out' data are truncated in this example for better readability.


ike V=root:0: IKEv2 exchange=SA_INIT id=e5510944e15c7032/0000000000000000 len=630
ike 0: in E55...004
ike V=root:0:e5510944e15c7032/0000000000000000:30: responder received SA_INIT msg
ike V=root:0:e5510944e15c7032/0000000000000000:30: VID forticlient connect license 4C53427B6D465D1B337BB755A37A7FEF706B9317F67F0000
ike V=root:0:e5510944e15c7032/0000000000000000:30: VID Fortinet Endpoint Control B4F01CA951E9DA8D0BAFBBD34AD3044E906B9317F67F0000
ike V=root:0:e5510944e15c7032/0000000000000000:30: VID Forticlient EAP Extension C1DC4350476B98A429B91781914CA43E808F013697010000
ike V=root:0:e5510944e15c7032/0000000000000000:30: received notify type FRAGMENTATION_SUPPORTED
ike V=root:0:e5510944e15c7032/0000000000000000:30: received notify type NAT_DETECTION_SOURCE_IP
ike V=root:0:e5510944e15c7032/0000000000000000:30: received notify type NAT_DETECTION_DESTINATION_IP
ike V=root:0:e5510944e15c7032/0000000000000000:30: received notify type SIGNATURE_HASH_ALGORITHMS
ike V=root:0:e5510944e15c7032/0000000000000000:30: incoming proposal:
ike V=root:0:e5510944e15c7032/0000000000000000:30: proposal id = 1:
ike V=root:0:e5510944e15c7032/0000000000000000:30: protocol = IKEv2:
ike V=root:0:e5510944e15c7032/0000000000000000:30: encapsulation = IKEv2/none
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=ENCR, val=AES_CBC (key_len = 128)
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=INTEGR, val=AUTH_HMAC_SHA2_256_128
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA2_512
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA2_384
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA2_256
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=DH_GROUP, val=MODP2048.
ike V=root:0:e5510944e15c7032/0000000000000000:30: proposal id = 2:
ike V=root:0:e5510944e15c7032/0000000000000000:30: protocol = IKEv2:
ike V=root:0:e5510944e15c7032/0000000000000000:30: encapsulation = IKEv2/none
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=ENCR, val=AES_CBC (key_len = 256)
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=INTEGR, val=AUTH_HMAC_SHA2_256_128
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA2_512
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA2_384
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA2_256
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=DH_GROUP, val=MODP2048.
ike V=root:0:e5510944e15c7032/0000000000000000:30: matched proposal id 2
ike V=root:0:e5510944e15c7032/0000000000000000:30: proposal id = 2:
ike V=root:0:e5510944e15c7032/0000000000000000:30: protocol = IKEv2:
ike V=root:0:e5510944e15c7032/0000000000000000:30: encapsulation = IKEv2/none
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=ENCR, val=AES_CBC (key_len = 256)
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=INTEGR, val=AUTH_HMAC_SHA2_256_128
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=PRF, val=PRF_HMAC_SHA2_256
ike V=root:0:e5510944e15c7032/0000000000000000:30: type=DH_GROUP, val=MODP2048.
ike V=root:0:e5510944e15c7032/0000000000000000:30: lifetime=86400
ike V=root:0:e5510944e15c7032/0000000000000000:30: SA proposal chosen, matched gateway TEST_VPN
ike V=root:0:TEST_VPN:TEST_VPN: created connection: 0x555f72cf60 25 10.5.140.103->10.5.143.160:55401.
ike V=root:0:TEST_VPN:30: processing notify type NAT_DETECTION_SOURCE_IP
ike V=root:0:TEST_VPN:30: processing NAT-D payload
ike V=root:0:TEST_VPN:30: NAT detected: PEER
ike V=root:0:TEST_VPN:30: process NAT-D
ike V=root:0:TEST_VPN:30: processing notify type NAT_DETECTION_DESTINATION_IP
ike V=root:0:TEST_VPN:30: processing NAT-D payload
ike V=root:0:TEST_VPN:30: NAT detected: ME PEER
ike V=root:0:TEST_VPN:30: process NAT-D
ike V=root:0:TEST_VPN:30: processing notify type FRAGMENTATION_SUPPORTED
ike V=root:0:TEST_VPN:30: processing notify type SIGNATURE_HASH_ALGORITHMS
ike V=root:0:TEST_VPN:30: enable FortiClient endpoint compliance check, use 169.254.1.1
ike 0:TEST_VPN:30: FCT EAP 2FA extension vendor ID received
ike V=root:0:TEST_VPN:30: responder preparing SA_INIT msg
ike V=root:0:TEST_VPN:30: generate DH public value request queued
ike V=root:0:TEST_VPN:30: responder preparing SA_INIT msg
ike V=root:0:TEST_VPN:30: compute DH shared secret request queued
ike V=root:0:TEST_VPN:30: responder preparing SA_INIT msg
ike V=root:0:TEST_VPN:30: create NAT-D hash local 10.5.140.103/4500 remote 10.5.143.160/55401
ike 0:TEST_VPN:30: out E55...02E
ike V=root:0:TEST_VPN:30: sent IKE msg (SA_INIT_RESPONSE): 10.5.140.103:4500->10.5.143.160:55401, len=424, vrf=0, id=e5510944e15c7032/e820d4ff128e28f3, oif=25
ike 0:TEST_VPN:30: IKE SA e5510944e15c7032/e820d4ff128e28f3 SK_ei 32:F568A1ED0EB142C00A99A54437C81046B5B38FF7594CA98B7399C3C3AAD986C6
ike 0:TEST_VPN:30: IKE SA e5510944e15c7032/e820d4ff128e28f3 SK_er 32:F7ADBC6A798113694259A8B657DA2BC502B29F9454DE5A53C8665C3A4998D530
ike 0:TEST_VPN:30: IKE SA e5510944e15c7032/e820d4ff128e28f3 SK_ai 32:2C4F2A64430AE01359AAF59F8B2EFD94747C407E2E7853BDEDC377A46BF44060
ike 0:TEST_VPN:30: IKE SA e5510944e15c7032/e820d4ff128e28f3 SK_ar 32:6AF9C7DE4D32583176CB98853A212AA7E1F514D10125314138AD56ED04E5B588
ike V=root:0: comes 10.5.143.160:55401->10.5.140.103:4500,ifindex=25,vrf=0,len=552....
ike V=root:0: IKEv2 exchange=AUTH id=e5510944e15c7032/e820d4ff128e28f3:00000001 len=548
ike 0: in E55...149
ike V=root:0:TEST_VPN:30: encrypted fragment 1 of 2 queued
ike V=root:0: comes 10.5.143.160:55401->10.5.140.103:4500,ifindex=25,vrf=0,len=152....
ike V=root:0: IKEv2 exchange=AUTH id=e5510944e15c7032/e820d4ff128e28f3:00000001 len=148
ike 0: in E55...A4A
ike V=root:0:TEST_VPN:30: encrypted fragment 2 of 2 queued
ike 0:TEST_VPN:30: dec E55...008
ike 0:TEST_VPN:30: dec E55...FFF
ike V=root:0:TEST_VPN:30: reassembled fragmented message
ike V=root:0:TEST_VPN:30: responder received AUTH msg
ike V=root:0:TEST_VPN:30: processing notify type INITIAL_CONTACT
ike V=root:0:TEST_VPN:30: processing notify type FORTICLIENT_CONNECT
ike V=root:0:TEST_VPN:30: received FCT data len = 300, data = 'VER=1
FCTVER=7.4.6.2001
UID=24EF73556E8545D0AAC9918D4D588E74
IP=10.5.143.160
MAC=00-67-72-61-43-02;00-67-72-61-43-01;
HOST=test_windows_VPN
USER=fortinet
OSVER=Microsoft Windows 8.0 Professional Edition, 64-bit (build 9200)
REG_STATUS=0
EMSSN=FCTEMSXXXXXXXXXX
EMSID=00000000000000000000000000000000
'
ike V=root:0:TEST_VPN:30: received FCT-UID : 24EF73556E8545D0AAC9918D4D588E74
ike V=root:0:TEST_VPN:30: received EMS SN : FCTEMSXXXXXXXXXX
ike V=root:0:TEST_VPN:30: received EMS tenant ID : 00000000000000000000000000000000
ike V=root:0:TEST_VPN:30: peer identifier IPV4_ADDR 10.5.143.160
ike V=root:0:TEST_VPN:30: re-validate gw ID
ike V=root:0:TEST_VPN:30: gw validation OK
ike V=root:0:TEST_VPN:30: responder preparing EAP identity request
ike 0:TEST_VPN:30: enc 270...102
ike 0:TEST_VPN:30: out E55...0D0
ike V=root:0:TEST_VPN:30: sent IKE msg (AUTH_RESPONSE): 10.5.140.103:4500->10.5.143.160:55401, len=128, vrf=0, id=e5510944e15c7032/e820d4ff128e28f3:00000001, oif=25


  • FortiGate will then wait for the FortiClient to provide user credentials, but the latter fails to provide them within the negotiation timeout period. The negotiated SPI expires on the FortiGate.


ike V=root:0:TEST_VPN:30: negotiation timeout, deleting
ike V=root:0:TEST_VPN: connection expiring due to phase1 down
ike V=root:0:TEST_VPN: going to be deleted


  • After the credentials are finally provided, FortiClient attempts to continue the Phase 1 negotiation using the expired SPI.

  • Since the SPI is no longer valid, FortiGate responds with invalid IKE request SPI.


ike V=root:0: comes 10.5.143.160:55401->10.5.140.103:4500,ifindex=25,vrf=0,len=100....
ike V=root:0: IKEv2 exchange=AUTH id=e5510944e15c7032/e820d4ff128e28f3:00000002 len=96
ike 0: in E55...436
ike V=root:0: invalid IKE request SPI e5510944e15c7032/e820d4ff128e28f3:00000002


  • FortiClient continues retrying the connection using the expired SPI, and after multiple retransmissions it eventually reports the error 'IKE message other than DPD retransmits to maximum'.


This situation is also more likely to occur when MFA (Multi-Factor Authentication) is enabled, as the user may require additional time to complete the authentication process.

In this scenario, the recommended action is to increase the Phase 1 negotiation timeout value.

config vpn ipsec phase1-interface
    edit TEST_VPN
        set negotiate-timeout 120
    next
end


By default, the negotiation timeout is set to 30 seconds. In addition, the FortiClient credential prompt timeout is controlled by the '<xauth_timeout>' parameter in the FortiClient XML profile. This value can be configured between 120 and 300 seconds (with a default of 120 seconds). See IKE settings.

To ensure consistent behavior between FortiClient and FortiGate, both the Phase 1 VPN parameters and the FortiClient 'xauth_timeout' setting should be reviewed and aligned accordingly. It is important to allow sufficient time for users to complete credential entry and MFA verification.

Â