IPsec failure on Phase1 but VPN tunnel listed as N/A ?
I've been setting up SSO with SAML for our IOS devices and I've set it up on a completely different port and WAN IP than the IPsec for our Windows machines (which are working fine). I've got the SSO working to the point that the SSO asks to login and and then passes back to the FortiClient and this then starts connecting but then after a while errors saying "the VPN session failed to connect in a timely manner" so I've checked the FortiAnalyzer which shows it's an issue with "Peer SA proposal does not match local policy" so I've confirmed all the settings are correct on both sides and they are however the problem is that when I've setup IPsec on these before and there's a mismatch the FortiAnalyzer still shows me which VPN tunnel the endpoint is trying to connect to so I'm ok troubleshooting the VPN issue itself but as I've checked the settings are correct then why does it show as N/A and not the IPsec name I've given it for the IOS devices (in case it's related to the cause) ?
Hope that makes sense.
Thanks
