Question
IPSec - duplicate connection detected on name insert
Hello I' m trying to build a VPN tunnel between 2 fortigates (FGT100A single <-> FGT110C cluster both in v3.00 MR7 patch 7), have configured all the same, " interface mode" , easy PSK, small phase1 & 2 names, and I' m getting this error:
duplicate connection detected on name insert, dropping this connection get tunnel info error.I have tried: - wait for the phase1 & 2 timeout - easier pre shared key - deleting all routes, policies, phase 1 & phase 2 linked to this VPN and recreating them - change the phase 1 and phase 2 names by adding a trailer " t" I have around 40 VPN tunnels from multi vendors (checkpoint, fortinet, PIX, ..) never seen that before. Here' s the log on FGT110C side:
0:VPNSSB35t:2650977: responder: main mode get 1st message... 0:VPNSSB35t:2650977: VID RFC 3947 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-08 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-07 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-06 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-05 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-04 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-03 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-02 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-02 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-01 0:VPNSSB35t:2650977: VID draft-ietf-ipsec-nat-t-ike-00 0:VPNSSB35t:2650977: VID DPD 0:VPNSSB35t:2650977: negotiation result 0:VPNSSB35t:2650977: proposal id = 1: 0:VPNSSB35t:2650977: protocol id = ISAKMP: 0:VPNSSB35t:2650977: trans_id = KEY_IKE. 0:VPNSSB35t:2650977: encapsulation = IKE/none 0:VPNSSB35t:2650977: type=OAKLEY_ENCRYPT_ALG, val=3DES_CBC. 0:VPNSSB35t:2650977: type=OAKLEY_HASH_ALG, val=SHA. 0:VPNSSB35t:2650977: type=AUTH_METHOD, val=PRESHARED_KEY. 0:VPNSSB35t:2650977: type=OAKLEY_GROUP, val=1024. 0:VPNSSB35t:2650977: ISKAMP SA lifetime=28800 0:VPNSSB35t:2650977: selected NAT-T version: RFC 3947 0:VPNSSB35t:2650977: cookie 1f62f8dce1c7c06e/92bf9de2dfb361aa 0:VPNSSB35t:2650977: sent IKE msg (ident_r1send): myFGT110C:500->myFGT100A:500, len=120 VPNSSB35t: Responder: sent myFGT100A main mode message #1 (OK) 0:VPNSSB35t: link fail 3 myFGT100A->myFGT100A:500 dpd=2 0:VPNSSB35t: created DPD triggered connection: 0x8c7b448 3 myFGT100A->myFGT100A:500. 0:VPNSSB35t: new connection. 0:VPNSSB35t: duplicate connection detected on name insert, dropping this connection 0:VPNSSB35t: get tunnel info error. diag d0: comes myFGT100A:500->myFGT110C:500,ifindex=3.... 0: exchange=Identity Protection id=1f62f8dce1c7c06e/0000000000000000 len=320 0: found VPNSSB35t myFGT110C 3 -> myFGT100A:500 0:VPNSSB35t:2650977: retransmission, re-send last message 0:VPNSSB35t:2650977: sent IKE msg (retransmit): myFGT110C:500->myFGT100A:500, len=120 0:VPNSSB35t:2650977: sent IKE msg (P1_RETRANSMIT): myFGT110C:500->myFGT100A:500, len=120Any idea ? rebooting it (we are not on Win***)? Regards
