Skip to main content
mhemambika
Staff
Staff
October 26, 2024

Troubleshooting Tip: Unable to select high encryption options such as 3DES or AES when configuring the IPsec tunnel

  • October 26, 2024
  • 0 replies
  • 1243 views

Description

This article describes a situation where high-encryption 3DES and AES cannot be selected in the IPsec tunnel configuration, along with potential causes for this issue.

Scope

Applicable to FortiGate versions.

Solution

Check device compatibility:

It is important to ensure that the hardware or software FortiGate device supports high encryption algorithms, as some older devices may not support AES or 3DES.

 

This is how it looks when configuring over the GUI:

 

Screenshot 2026-03-27 193308.jpg

 

Consider the following example:

 

get system status
Version: FortiGate-400F v7.2.10,build1706,240918 (GA.M)
Security Level: 0
Virus-DB: 1.00000(2018-04-09 18:07)
Extended DB: 1.00000(2018-04-09 18:07)
Extreme DB: 1.00000(2018-04-09 18:07)
AV AI/ML Model: 3.00243(2024-08-20 00:45)
IPS-DB: 6.00741(2015-12-01 02:30)
IPS-ETDB: 6.00741(2015-12-01 02:30)
APP-DB: 6.00741(2015-12-01 02:30)
FMWP-DB: 24.00090(2024-09-23 14:32)
INDUSTRIAL-DB: 6.00741(2015-12-01 02:30)
IPS Malicious URL Database: 1.00001(2015-01-01 01:01)
IoT-Detect: 0.00000(2022-08-17 17:31)
Serial-Number: FG4XXXXXXXXXXXXX
BIOS version: 06000101
System Part-Number: P27290-05
Log hard disk: Not available
Hostname: Firewall_PRIMARY
Operation Mode: NAT
Current virtual domain: root
Max number of virtual domains: 10
Virtual domains status: 1 in NAT mode, 0 in TP mode
Virtual domain configuration: disable
FIPS-CC mode: disable
Current HA mode: a-p, primary
Cluster uptime: 6 days, 20 hours, 37 minutes, 12 seconds
Cluster state change time: 2024-09-26 17:28:37
License Status: Low-Encryption(LENC)

 

The FortiGate device displays a license status of Low-Encryption (LENC), indicating that it supports only low encryption algorithms.

 

In cases like this, it is recommended to upgrade to a full encryption device by acquiring a strong encryption upgrade license key.

 

In order to apply a strong encryption license key (or to apply a LENC key) obtained for the device, use the following command:

 

execute crypto-license <Encryption-key>

 

Note:

The LENC license also utilizes TLS version 1.0, which is deprecated and no longer supported by FortiGuard Server. As a result, validation attempts are unsuccessful due to the inability to negotiate a more secure encryption cipher with this license. More information here:

Troubleshooting Tip: Connectivity issue with FortiGuard servers due to SSL_connect failure (LENC license)


Related documents:

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!