Skip to main content
tana
Staff
Staff
July 9, 2026

Troubleshooting Tip: Unable to set negotiate-timeout lower than 15 in IKE version 1 IPsec tunnel

  • July 9, 2026
  • 0 replies
  • 201 views

Description

This article describes an issue where it is not possible to set the negotiate-timeout lower than 15 after upgrading to FortiOS v7.6.7.

Scope

FortiOS v7.6.7.

Solution

Verify the issue:
The following symptoms may be observed:

The FortiGate CLI returns the following error when trying to configure 'set negotiate-timeout' to a value of 15 or lower in FortiGate IPSEC VPN phase1-interface settings.

FGT # config vpn ipsec phase1-interface

FGT  (phase1-interface) # edit "test"
FGT  (test) # set negotiate-timeout 15

FGT  (test) # next
Please set auto-transport-threshold shorter than negotiate-timeout.
object check operator error, -39, discard the setting
Command fail. Return code -39


When using an IKE version 1 tunnel, setting negotiate-timeout to less than or equal than the auto-transport-threshold would give an error, while auto-transport-threshold can only be set when using IKEv2 tunnel.


Workaround:
Change the IKE version to 2 first, then set auto-transport-threshold to 10, only then is it possible to set negotiate-timeout to 15, finally revert the IKE version to 1.

Solution (patch fix):
The issue is related to a known issue in FortiOS v7.6.7.

This known issue will be patch fix on the next patch versions: FortiOS versions 7.6.8 and 8.0.1.