Skip to main content
Mourad_Aloui
New Member
September 25, 2019
Question

IPSec negotiation failure

  • September 25, 2019
  • 2 replies
  • 9439 views

 

 

I have a probleme with negotiation 

 

    2 replies

    ede_pfau
    SuperUser
    SuperUser
    September 25, 2019

    If (IF) this is truly a phase2 error, then it might be

    - mismatching QM selectors (a.k.a. "protected domains")

    - PFS setting mismatch

    - if this is a dial-in tunnel: failure to assign client IP address

     

    Mourad_Aloui
    New Member
    September 26, 2019

    Hello,

    Thanks for your feedback. The problem still exists, today in the morning the tunnel is down but after an hour it is up.

     

    emnoc
    New Member
    September 26, 2019

    is DPD enable?

    what's the other end ? ( fgt panw csco forcepoint jnpr ) 

    if you "vpn ike gateway clear" does that speed up the recover ?

     

    Ken Felix

    Mourad_Aloui
    New Member
    September 26, 2019

    The remote device is FortiGate.

    The recover speedly