Skip to main content
jltrepanier
New Member
May 6, 2014
Question

Error code -56 when trying to set L2TP/IPsec using Cookbook 507

  • May 6, 2014
  • 9 replies
  • 16240 views
Trying to Configuer my FortiGate 60D unit as an L2TP/IPsec server using the latess Cookbook 507 I get to CLI Console editing Phase2 step and at the end I get ' phase1name' must be set. Message from Console: FGT60D4614000741 (L2TP_P2) # show config vpn ipsec phase2 edit " L2TP_P2" set proposal 3des-sha1 aes128-sha1 set encapsulation transport-mode next end FGT60D4614000741 (L2TP_P2) # end node_check_object fail! for phase1name Attribute ' phase1name' MUST be set. Command fail. Return code -56 I follow the cookbook step by step and I can' t find what I missed. Please help

    9 replies

    emnoc
    New Member
    May 6, 2014
    What' s your phase1 name? Please follow this link on my blog for a l2tp-ipsec config that works for android to linux. http://socpuppet.blogspot.com/2013/02/l2tp-setup-fortigate-200b-mr3p12.html
    jltrepanier
    New Member
    May 6, 2014
    As per the Cookbook the Phase1 is named L2TP I went to see your blog, *EDIT* but I don' t see anything that pops out as something I may have forgotten. I just spotted something be right back. *EDIT2* Tried to add set phase1name " l2tp_dialupRA01" FGT60D4614000741 (L2TP_P2) # set phase1name " L2TP_P1" entry not found in datasource value parse error before ' L2TP_P1' Command fail. Return code -3
    ede_pfau
    SuperUser
    SuperUser
    May 6, 2014
    hello, as it says: you MUST set the phase1name parameter before entering ' next' . The Cookbook example is twofold: first they describe what to configure in the WebGUI, then you have to enter one additional parameter (' set encapsulation' ) in the CLI - this parameter is not available in the WebGUI. The error message tells me that you have not configured a phase2 in the WebGUI first.
    jltrepanier
    New Member
    May 6, 2014
    As I said I followed the steps, so yes the gui step was done before the cli config step.
    jltrepanier
    New Member
    May 6, 2014
    Here are the screen shots of the GUI: 1/2
    jltrepanier
    New Member
    May 6, 2014
    Here are the screen shots of the GUI: 2/2
    ede_pfau
    SuperUser
    SuperUser
    May 6, 2014
    From the screenshot I see that your phase1 was created in ' Interface Mode' . Your phase2 (as per CLI) is not in ' Interface Mode' but ' Policy Mode' . You cannot mix both VPN types. Unfortunately, one cannot change the ' Mode' after creation. Delete phase2 and phase1 and recreate phase1, disable ' Interface Mode' check box, and proceed as before.
    jltrepanier
    New Member
    May 6, 2014
    Thanks Ede_pfau that was it.
    ede_pfau
    SuperUser
    SuperUser
    May 6, 2014
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!