IPSec Client Vpn
I have a FortiGate VM deployed on Microsoft Azure, and I’m trying to configure an IPsec Client-to-Site VPN.
The current situation is:
* FortiGate VM is running on Azure.
* UDP 500 and UDP 4500 are allowed in the Azure Network Security Group (NSG) and Azure networking.
* The IPsec VPN client is able to reach the FortiGate.
* Phase 1 is established successfully.
* However, Phase 2 does not come up, and the VPN client cannot establish the VPN connection successfully.
I have already verified that UDP 500 and 4500 are allowed, but the issue still occurs.
My questions:
1. What are the most common reasons for IPsec Phase 2 failing on a FortiGate VM running on Azure when Phase 1 is already established?
2. Are there any Azure-specific requirements or settings that I should check for IPsec VPN, such as NSG rules, Public IP, routing, NAT-T, or IP forwarding?
3. What FortiGate debug commands would you recommend to identify why Phase 2 is failing?
Any guidance or troubleshooting steps would be highly appreciated.
