Skip to main content
khalilbouzaiene1
Visitor III
March 13, 2024
Question

Ipsec Tunnel problem

  • March 13, 2024
  • 2 replies
  • 1247 views

Hey everyone,

Currently, I'm dealing with a situation where I have two sites, one equipped with a Fortigate firewall and the other with pfSense. My goal is to establish an IPsec tunnel between them. However, the version of Fortigate I'm working with is 7.0.12, which only supports the DES encryption algorithm. Additionally, for authentication, we only have SHA-256, 384, and 512 available.

On the other hand, pfSense supports different encryption algorithms. Given these limitations and the requirement to maintain the current version of Fortigate without updates, what would be the best solution to address this issue?

Thanks in advance for any insights or recommendations you can provide.

PS: It's crucial that we maintain the current version of Fortigate and cannot update it

 

2 replies

khalilbouzaiene1
Visitor III
March 13, 2024

this is encryption algorithme in the fortigate : 

ipsec1.png

and this the encryption algorithme  in the pfsense : 

ipsec2.png

ozkanaltas
Valued Contributor III
March 13, 2024

Hello @khalilbouzaiene1 ,

 

I found some articles about your problem. Can you check the low encryption status with this command? "get system status | grep "License Status"

 

https://community.fortinet.com/t5/FortiCache/Technical-Tip-Low-Encryption-LENC-device-FAQ/ta-p/190323?externalID=FD37333

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Option-to-set-Algorithm-and-ban-cipher-is-not/ta-p/197316

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!