Skip to main content
Israt24Fortinet
New Member
March 23, 2024
Question

firmware

  • March 23, 2024
  • 2 replies
  • 941 views

I am configuring ipsec vpn on FortiGate 60F firewall and 200F firewall. In 60F, fortiguard option, it says, "firmware and general update is expired. Firmware version is v6.4.6 build 6083 (GA). Do I need to update the firmware, because IP sec phase1 is down. If not, what can be the reason for ipsec phase 1 for being down?

2 replies

AEK
SuperUser
SuperUser
March 23, 2024

In phase 1 proposal check if encryption-authentication pairs and Diffie-Hellman Groups match between the two FortiGates.

 

Run the below commands on the receiver while initiating the tunnel on the initiator FG.

diagnose debug console timestamp enable
diagnose debug application ike -1
diagnose debug enable

 

AEK
hbac
Staff & Editor
Staff & Editor
March 23, 2024

Hi @Israt24Fortinet,

 

Your "firmware and general update" license is expired but it shouldn't affect the IPsec tunnel. You can run ike debug to see why it is failing. 

 

Regards, 

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!