Skip to main content
Oscar_Wee
Staff
Staff
March 20, 2025

Troubleshooting Tip: Site-to-Site IPsec VPN phase 1 not forming due to Config ID error message on remote firewall.

  • March 20, 2025
  • 0 replies
  • 642 views
Description This article describes how to resolve Site-to-Site IPsec VPN phase 1 not forming due to a Config ID error message on the remote firewall.
Scope FortiGate.
Solution

Example of Config ID error message on remote firewall:

 

config id mismatch.jpg

 

To troubleshoot this, remove the local ID.

 

Remove local ID.jpg

 

Result: Phase 1 is formed.

 

Note :

  • In a scenario with multiple dial-up IPsec VPN tunnels sharing a single WAN connection, configuring peerID is crucial for directing connections to the correct tunnel, especially when multiple tunnels are involved.
  • Without a defined peerID, all connections default to the first tunnel, potentially causing routing issues.
  • Additionally, aggressive mode must be enabled in phase 1 settings to facilitate this process, as it allows for more flexible negotiation and identification.
  • The local ID, exchanged during phase 1, serves as an additional verification parameter on the remote side, enabling it to filter and permit only connections from specific identities, thereby enhancing security and ensuring proper tunnel association.

 

Related article:

Troubleshooting Tip: IPsec VPN tunnels

Technical Tip: Use of PeerID and LocalID in IPsec VPN between two FortiGates

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!