Fortigate to Strongswan tunnel, failing phase 1
Good morning. I'm having trouble getting a tunnel between a Fortigate 100D and Strongswan running on TomatoUSB. I've tried so many different combinations and have probably complicated this more than it should be.. Would you please help point me in the right direction?
Fortigate Phase 1 & 2
config vpn ipsec phase1-interface
edit "VPN1"
set interface "wan1"
set keylife 28800
set proposal 3des-sha1
set localid "vpn.fortigate123.org"
set dpd disable
set dhgrp 14 5 2
set remote-gw w.x.y.z
set psksecret not_my_actual_password
next
end
config vpn ipsec phase2-interface
edit "Ph2_VPN1"
set phase1name "VPN1"
set proposal aes128-sha1
set pfs disable
set replay disable
set keepalive enable
set auto-negotiate enable
set keylifeseconds 3600
set src-subnet 192.168.1.0 255.255.255.0
set dst-subnet 192.168.5.0 255.255.255.0
next
end
Strongswan file /etc/ipsec.conf
# ipsec.conf - strongSwan IPsec configuration file
# basic configuration
config setup
# strictcrlpolicy=yes
# uniqueids = no
conn %default
ikelifetime=8h
keylife=1h
rekeymargin=3m
keyingtries=%forever
keyexchange=ikev1
authby=psk
ike=3des-sha1-modp2048
esp=3des-sha1-modp2048
forceencaps=yes
conn VPN1
type=tunnel
authby=secret
auto=start
keyexchange=ikev1
ike=3des-sha1-modp2048
left=w.x.y.z
leftsubnet=192.168.5.0/24
leftid=@bain.strongswan123.org
leftfirewall=no
right=a.b.c.d
rightsubnet=192.168.1.0/24
rightid=@vpn.fortigate123.org
compress=no
esp=aes128-sha1
keyingtries=%forever
Strongswan file /etc/ipsec.secrets
/etc/ipsec.secrets - strongSwan IPsec secrets file
@bain.strongswan123.org @vpn.fortigate123.org : PSK not_my_actual_password
diag vpn ike gateway list
name: VPN1
version: 1
interface: wan1 26
addr: a.b.c.d:500 -> w.x.y.z:500
created: 19s ago
IKE SA: created 1/1
IPsec SA: created 1/1
id/spi: 7369 2bbd1198da4e8cd5/0000000000000000
direction: responder
status: connecting, state 3, started 19s ago
diagnose debug app ike 255
WCUFGT02 # ike 0:V:7417: negotiation timeout, deleting
ike 0:Site-Site-MCB: connection expiring due to phase1 down
ike 0:Site-Site-MCB: deleting
ike 0:Site-Site-MCB: flushing
ike 0:Site-Site-MCB: flushed
ike 0:Site-Site-MCB: deleted
ike 0:Site-Site-MCB: schedule auto-negotiate
ike 0:Site-Site-MCB:7418: initiator: main mode is sending 1st message...
ike 0:Site-Site-MCB:7418: cookie 65d55c36e44631e2/0000000000000000
ike 0:Site-Site-MCB:7418: out 65D55C36E44631E200000000000000000110020000000000000002CC0D0001E40000000100000001000001D80101000C0300002801010000800B0001000C00040001518080010007800E008080030001800200048004000E0300002802010000800B0001000C00040001518080010007800E00808003000180020004800400050300002803010000800B0001000C00040001518080010007800E010080030001800200048004000E0300002804010000800B0001000C00040001518080010007800E01008003000180020004800400050300002405010000800B0001000C0004000151808001000580030001800200048004000E0300002406010000800B0001000C000400015180800100058003000180020004800400050300002807010000800B0001000C00040001518080010007800E008080030001800200028004000E0300002808010000800B0001000C00040001518080010007800E00808003000180020002800400050300002809010000800B0001000C00040001518080010007800E010080030001800200028004000E030000280A010000800B0001000C00040001518080010007800E0100800300018002000280040005030000240B010000800B0001000C0004000151808001000580030001800200028004000E000000240C010000800B0001000C000400015180800100058003000180020002800400050D0000144A131C81070358455C5728F20E95452F0D0000147D9419A65310CA6F2C179D9215529D560D000014CD60464335DF21F87CFDB2FC68B6A4480D00001490CB80913EBB696E086381B5EC427B1F0D00001416F6CA16E4A4066D83821A0F0AEAA8620D0000144485152D18B6BBCD0BE8A8469579DDCC0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE0005029E
ike 0:Site-Site-MCB:7418: sent IKE msg (ident_i1send): a.b.c.d:500->w.x.y.z:500, len=716, id=65d55c36e44631e2/0000000000000000
ike 0:Site-Site-MCB:7418: out 65D55C36E44631E200000000000000000110020000000000000002CC0D0001E40000000100000001000001D80101000C0300002801010000800B0001000C00040001518080010007800E008080030001800200048004000E0300002802010000800B0001000C00040001518080010007800E00808003000180020004800400050300002803010000800B0001000C00040001518080010007800E010080030001800200048004000E0300002804010000800B0001000C00040001518080010007800E01008003000180020004800400050300002405010000800B0001000C0004000151808001000580030001800200048004000E0300002406010000800B0001000C000400015180800100058003000180020004800400050300002807010000800B0001000C00040001518080010007800E008080030001800200028004000E0300002808010000800B0001000C00040001518080010007800E00808003000180020002800400050300002809010000800B0001000C00040001518080010007800E010080030001800200028004000E030000280A010000800B0001000C00040001518080010007800E0100800300018002000280040005030000240B010000800B0001000C0004000151808001000580030001800200028004000E000000240C010000800B0001000C000400015180800100058003000180020002800400050D0000144A131C81070358455C5728F20E95452F0D0000147D9419A65310CA6F2C179D9215529D560D000014CD60464335DF21F87CFDB2FC68B6A4480D00001490CB80913EBB696E086381B5EC427B1F0D00001416F6CA16E4A4066D83821A0F0AEAA8620D0000144485152D18B6BBCD0BE8A8469579DDCC0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE0005029E
ike 0:Site-Site-MCB:7418: sent IKE msg (P1_RETRANSMIT): a.b.c.d:500->w.x.y.z:500, len=716, id=65d55c36e44631e2/0000000000000000
ike 0:Site-Site-MCB:7418: out 65D55C36E44631E200000000000000000110020000000000000002CC0D0001E40000000100000001000001D80101000C0300002801010000800B0001000C00040001518080010007800E008080030001800200048004000E0300002802010000800B0001000C00040001518080010007800E00808003000180020004800400050300002803010000800B0001000C00040001518080010007800E010080030001800200048004000E0300002804010000800B0001000C00040001518080010007800E01008003000180020004800400050300002405010000800B0001000C0004000151808001000580030001800200048004000E0300002406010000800B0001000C000400015180800100058003000180020004800400050300002807010000800B0001000C00040001518080010007800E008080030001800200028004000E0300002808010000800B0001000C00040001518080010007800E00808003000180020002800400050300002809010000800B0001000C00040001518080010007800E010080030001800200028004000E030000280A010000800B0001000C00040001518080010007800E0100800300018002000280040005030000240B010000800B0001000C0004000151808001000580030001800200028004000E000000240C010000800B0001000C000400015180800100058003000180020002800400050D0000144A131C81070358455C5728F20E95452F0D0000147D9419A65310CA6F2C179D9215529D560D000014CD60464335DF21F87CFDB2FC68B6A4480D00001490CB80913EBB696E086381B5EC427B1F0D00001416F6CA16E4A4066D83821A0F0AEAA8620D0000144485152D18B6BBCD0BE8A8469579DDCC0D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE0005029E
ike 0:Site-Site-MCB:7418: sent IKE msg (P1_RETRANSMIT): a.b.c.d:500->w.x.y.z:500, len=716, id=65d55c36e44631e2/0000000000000000
ike 0:Site-Site-MCB:7418: negotiation timeout, deleting
ike 0:Site-Site-MCB: connection expiring due to phase1 down
Any help would be appreciated!
