IPsec VPN tunnel between 501e and Cisco ASA 5516
I'm working to set up an IPsec tunnel between a 501e running 6.4.6 firmware and a Cisco 5516. We're using 3DES/SHA1/DH Grp2 for both Phase 1 and Phase 2. The Fortigate show the tunnel comes up and looks normal, but if we initiate communications from the Fortigate side they fail and the Cisco reports encapsulation errors on Phase2. However if communications initiate from the Cisco side things work fine.
We've checked settings, routing, and policies on both sides and they seem to match.
Anyone have any suggestions on what else to check or try?
