Technical Tip: Unable to get IPsec VPN established after using SPA easy configuration key
Description | This article describes a solution for a situation where, following the SPA easy configuration key for FortiSASE on FortiOS v7.6.5+, the IPsec with FortiSASE remains down. |
Scope | Â FortiGate v7.6.5+, FortiSASE. |
Solution | The reason why the VPN is unable to activate is a mismatch between FortiOS and FortiSASE default DH group preset.
Related documents: Verifying and troubleshooting IPsec connection Troubleshooting Tip: FortiSASE SPA Troubleshooting Triage Troubleshooting Tip: IPsec VPN tunnels Troubleshooting Tip: IPSec VPN down due to 'mismatched DH group in KE payload' |
