Skip to main content
Contributor III
April 6, 2009
Question

error Invalid ESP packet detected (HMAC validation failed).

  • April 6, 2009
  • 6 replies
  • 6494 views
hello, I configured a VPN on a f310b (worm Fortigate-310B 3.00-b5408 (MR7) opposite, it is F5000. by moment, I have this message of error in the logs (Invalid ESP packet detected (HMAC validation failed). somebody among you already this error? ps: forgive my bad English thank you

    6 replies

    Contributor III
    April 6, 2009
    can you provide further information? seems to me that it is an encryption error... have you double checked the settings on the FortiGates? Do they both use the same encryption method?
    Contributor III
    April 6, 2009
    the method used is the encryption 3DES and authentification MD5 the pre-shared key is identical. They are configured in mode Main (ID Protection) Best regard
    fsbadmin1
    New Member
    April 7, 2009
    I had this happen recently on a new FG-60B. Support said sounded like corrupt firmware or a hardware issue. I reinstalled firmware using TFTP server to get a totally fresh OS, but that did not remedy. I RMA' d the unit after that, no explanation from support. Just got my new unit today, minus all the accessories that I was instructed to return with the original unit. Support just now claimed I was told NOT to include these things. I sent them the email instructing me to return them. So now im waiting on a power supply. if you RMA your unit, i suggest holding all accesoris, you can always return them later if your replacement does contain them. I would get ahold of support and get the RMA ball rolling now....I screwed around trying to figure it out myself for a few weeks, I found nothing at all...other than what has been mentioned here, confirming settings match etc. I would love to know what this problem is however! I hate not being able to figure things out. Frustrating. good luck.
    Contributor III
    April 8, 2009
    what have you tried to solve this issue by now? Have you run a sniffer, to see if the packets are entering the VPN tunnel? If so, have you had a look at the flow through the unit? If not, you can do so with: - diagnose debug enable - diagnose debug flow filter addr ' external gateway IP' - diagnose debug flow show console enable - diagnose debug trace start xxx (where xxx is the number of messages you want to trace) I highly recommend doing this if you have any problems with VPN Tunnels, routing or other traffic not going where it' s supposed to. This makes it a lot easier to find & solve problems. regards
    fsbadmin1
    New Member
    April 8, 2009
    when i was getting this error, my VPN tunnel was up, traffic was passing normally. the unit i sent back for RMA would lock up at seemingly random times, and require a power cycle to recover. this started out as once a day, and eventually several times a day. that is the error i had logged on both ends of the VPN, the FG-60B (rma' d) and the FG-60. when it locked up, it could not be accessed by any interface, nor pinged....but on the other end of the VPN the FG-60' s sessions still showed open sessions, although no traffic was passing thru. *note on the accessories i sent in that were not returned with new unit....support said the CSR who handled my RMA made an error instructing me to return the accessories and they are shipping me replacements. very quick solution to this by ForitNet' s support, thanks!
    Contributor III
    April 9, 2009
    hello and thank you for your councils. apparently, I receive spoofing on the interface network of my VPN. this would explain that. Good day
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.