Skip to main content
ahmetyilmaz
New Member
September 9, 2020
Question

IPSEC Fail

  • September 9, 2020
  • 1 reply
  • 4393 views

Hi All,

 

Some ip trying to connect over ipsec tunnel to our network. Why can't block IPS these?

 

Like this:

 

Message meets Alert condition

date=2020-09-08 time=06:51:12 devname=xxxxxxxx devid=xxxxxxxxxxx logid="0101037128" type="event" subtype="vpn" level="error" vd="root" eventtime=1599537072204809801 tz="+0300" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=216.218.206.78 locip=xxxxxxxx remport=23703 locport=500 outintf="wan1" cookies="3e35c70729dfedef/0000000000000000" user="N/A" group="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="N/A" status="failure" init="remote" mode="main" dir="inbound" stage=1 role="responder" result="ERROR"

    1 reply

    Markus
    New Member
    September 9, 2020

    Hello and welcome to the forums. In short: Because of how the FG handles connections (IPS is involved later) in the flow https://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-life-of-packet-52/LoP-packet-flow.htm You have to deal with local in policies, if you want to block such IPs (or regions etc.) https://forum.fortinet.com/tm.aspx?m=171342

     

    Best

    ahmetyilmaz
    New Member
    September 9, 2020

    Thank you very much for reply Markus. I couldn't find before Packet flow.

    Markus
    New Member
    September 10, 2020

    glad to help