Skip to main content
TobiasHan
New Member
July 28, 2017
Question

Fortigate Sophos VPN ISAKMP SA still negotiating

  • July 28, 2017
  • 2 replies
  • 6060 views

Hello,

 

i have a Fortigate 500D with Firmware v.5.4.2 and i try to build a VPN-Tunnel to a Sophos UTM 9.

 

I have made a VPN-Tunnel to the Remote Address (IKE Gateway) from the Sophos Firewall.

 

When i make a

diag vpn ike log-filter name diag debug app ike -1 diag debug enable

 

i get following output:

IPsec SA connect 35 xx.xxx.xxx.x->xx.xxx.xx.xxx:0 using existing connection config found IPsec SA connect 35 xx.xxx.xxx.x->xx.xxx.xx.xxx:500 negotiating ISAKMP SA still negotiating, queuing quick-mode request

 

 

what does the still negotiating mean? Is this the error?

 

With Best Regards TobiasHan

    2 replies

    TobiasHan
    TobiasHanAuthor
    New Member
    July 28, 2017

    Problem found. Wrong Remote IP Adress.

     

    Regards

    oheigl
    New Member
    July 28, 2017

    My guess is you need the same output from the Sophos Firewall, because something is wrong on the other side. The FortiGate doesn't seem to have a problem, but most of the time you only see the mismatch on one side of the VPN negotiation. Do you have some log output from the remote side?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!