ipsec tunnel was working, now "no matching IKEv1 phase1 configuration"
FGT1 internal1 is directly* connected to FGT2 wan1 and there is an ipsec interface vpn which was working fine but is now down.
I see the following debug at FGT1
diag deb app ike -1
diag deb en
ike 0: comes 172.a.b.122:500->172.a.b.121:500,ifindex=11...
[...]
ike 0: no IKEv1 phase1 configuration matching 172.a.b.122:500->172.a.b.121 11The full phase1-interface configurations have been verified to be correct and match. I don't know how to resolve ifindex to physical interface (I've seen ifindex mentioned somewhere in doco but can't find it now). The tunnel gateway on FGT1 is a secondary ip address.
I have also subsequently forced a psk mismatch with no change to the debug output.
FGT1 was recently updated from 4.1.4 to 4.3.18 with no known issues; another vpn is working fine. FGT2 is 4.3.14, update pending.
Any tips where to look next?
* "directly" is a digital radio link. There are no known issues with the link.
