Skip to main content
RolandBaumgaertner72
New Member
July 25, 2025
Solved

Change from SSL VPN to IPSec >> cant connect to IPsec

  • July 25, 2025
  • 10 replies
  • 1962 views

Hello,

 

we just changed a FG cluster and we have FG90G with 7.4.7. I know that 7.4.8 does not support SSL VPN anymore so I guess we have no other option than changing from SSL VPN to IPSec.

 

I am trying to build up the IPSec connection same way like the SSL VPN but I cant connect. Of course standard IPSec DialUp connection is easy and always works but since we have a lot of Groups and I want to control them with Policies I dont get it running.

 

Incomming Interface is clear, the same and I know that it doesnt block any traffic

Client address range I use the same object SSL VPN range

Accessible Networks all since I also have to route them to Azure and our VPNs (like SSL VPN)

PSK I checked many times, this is 100% correct

XAUTH Inherit from Policy

 

So in the IPSec to LAN policy I just copied from SSL VPN the same range and my TEST User, destination and service all.

 

I try to connect but I get in the Client a failure of wrong credentials and than VPN connection failed, check configuration and network. Diag Sniffer on the FG and my public IP I see incommung UDP 500 and 4500 but nothing more.

 

In the FG I get Action negotiate , Status failure , Result XAUTH authentication failed

 

When i change the XAUTH and put a user Group with my Test User I get another failure delete IPsec phase 1 SA

 

Am I missing something since this was always an easy task?

 

Thanks!

Best answer by RolandBaumgaertner72

I just checked it and while debugging it I tried with my Local User and it would not work, but my LDAP user works just fine...so I think this is solved!

 

Thanks!

10 replies

funkylicious
SuperUser
SuperUser
July 25, 2025
RolandBaumgaertner72
New Member
July 25, 2025

Hi,

 

I just tried with another range, SSL VPN with X.X.94.155-X.X.94.210 and IPSec with X.X.94.211-X.X.94.240 and I get the same mistake

 

funkylicious
SuperUser
SuperUser
July 25, 2025

are you using local user for connecting or a remote user from LDAP/RADIUS ?

can you post a sanitized configuration of your dialup ipsec configuration ?

"jack of all trades, master of none"
RolandBaumgaertner72
New Member
July 25, 2025

Hi,

 

I want to user LDAP User but for testing I just put my local test user in this Group

 

What do you mean with sanitized?

 

Incomming Interface is clear, the same and I know that it doesnt block any traffic

Client address range NOW the new IPSec range which is differnet to the SSL VPN

Accessible Networks ALL since I also have to route them to Azure and our VPNs (like SSL VPN)

PSK I checked many times, this is 100% correct

XAUTH Inherit from Policy

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!