Skip to main content
Brustolin
Explorer
January 6, 2023
Question

Multiple VPN IPSec using different IP's

  • January 6, 2023
  • 10 replies
  • 4469 views

Hello guys

 

Currently we have a necessity of deploying a lot of IPSec VPN's in different IP's from my WAN interface

For some reason that I don't know the VPN's only works if i enable "ping" with secondary addresses on Wan interface

 

Currently I have 30 IP's in secondary ips on my WAN. The FortiOS have a limitation of 32 IP's

If I don't enable ping, IPSec dont works and I receive this output

 

ike 0:ecea911495885ac4/0000000000000000:3203: responder: main mode get 1st message...
ike 0:ecea911495885ac4/0000000000000000:3203: VID DPD AFCAD71368A1F1C96B8696FC77570100
ike 0:ecea911495885ac4/0000000000000000:3203: VID FRAGMENTATION 4048B7D56EBCE88525E7DE7F00D6C2D3
ike 0:ecea911495885ac4/0000000000000000:3203: VID FRAGMENTATION 4048B7D56EBCE88525E7DE7F00D6C2D3C0000000
ike 0:ecea911495885ac4/0000000000000000:3203: VID FORTIGATE 8299031757A36082C6A621DE00000000
ike 0:ecea911495885ac4/0000000000000000:3203: negotiation result
ike 0:ecea911495885ac4/0000000000000000:3203: proposal id = 1:
ike 0:ecea911495885ac4/0000000000000000:3203: protocol id = ISAKMP:
ike 0:ecea911495885ac4/0000000000000000:3203: trans_id = KEY_IKE.
ike 0:ecea911495885ac4/0000000000000000:3203: encapsulation = IKE/none
ike 0:ecea911495885ac4/0000000000000000:3203: type=OAKLEY_ENCRYPT_ALG, val=AES_CBC, key-len=128
ike 0:ecea911495885ac4/0000000000000000:3203: type=OAKLEY_HASH_ALG, val=SHA.
ike 0:ecea911495885ac4/0000000000000000:3203: type=AUTH_METHOD, val=PRESHARED_KEY.
ike 0:ecea911495885ac4/0000000000000000:3203: type=OAKLEY_GROUP, val=MODP1536.
ike 0:ecea911495885ac4/0000000000000000:3203: ISAKMP SA lifetime=86400
ike 0:ecea911495885ac4/0000000000000000:3203: SA proposal chosen, matched gateway VPN_WINOV_SP
ike 0: found VPN_WINOV_SP 200.195.149.26 6 -> 170.231.15.66:500
ike 0:VPN_WINOV_SP:3203: peer is FortiGate/FortiOS (v0 b0)
ike 0:VPN_WINOV_SP:3203: cookie ecea911495885ac4/4fea753eb08576f2
ike 0:VPN_WINOV_SP:3203: out ECEA911495885AC44FEA753EB08576F20110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000148299031757A36082C6A621DE000000000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000
ike 0:VPN_WINOV_SP:3203: sent IKE msg (ident_r1send): 200.195.149.26:500->170.231.15.66:500, len=172, vrf=0, id=ecea911495885ac4/4fea753eb08576f2
ike 0: comes 170.231.15.66:500->200.195.149.26:500,ifindex=6,vrf=0....
ike 0: IKEv1 exchange=Identity Protection id=ecea911495885ac4/0000000000000000 len=172 vrf=0
ike 0: in ECEA911495885AC400000000000000000110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_WINOV_SP:3203: retransmission, re-send last message
ike 0:VPN_WINOV_SP:3203: out ECEA911495885AC44FEA753EB08576F20110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000148299031757A36082C6A621DE000000000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000
ike 0:VPN_WINOV_SP:3203: sent IKE msg (retransmit): 200.195.149.26:500->170.231.15.66:500, len=172, vrf=0, id=ecea911495885ac4/4fea753eb08576f2
ike 0:VPN_WINOV_SP:3203: out ECEA911495885AC44FEA753EB08576F20110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000148299031757A36082C6A621DE000000000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000
ike 0:VPN_WINOV_SP:3203: sent IKE msg (P1_RETRANSMIT): 200.195.149.26:500->170.231.15.66:500, len=172, vrf=0, id=ecea911495885ac4/4fea753eb08576f2
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: IPsec SA connect 6 200.195.149.26->170.231.15.66:0
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: using existing connection
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: config found
ike 0:VPN_WINOV_SP: request is on the queue
ike 0: comes 170.231.15.66:500->200.195.149.26:500,ifindex=6,vrf=0....
ike 0: IKEv1 exchange=Identity Protection id=ecea911495885ac4/0000000000000000 len=172 vrf=0
ike 0: in ECEA911495885AC400000000000000000110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_WINOV_SP:3203: retransmission, re-send last message
ike 0:VPN_WINOV_SP:3203: out ECEA911495885AC44FEA753EB08576F20110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000148299031757A36082C6A621DE000000000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000
ike 0:VPN_WINOV_SP:3203: sent IKE msg (retransmit): 200.195.149.26:500->170.231.15.66:500, len=172, vrf=0, id=ecea911495885ac4/4fea753eb08576f2
ike 0:VPN_WINOV_SP:3203: out ECEA911495885AC44FEA753EB08576F20110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000148299031757A36082C6A621DE000000000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000
ike 0:VPN_WINOV_SP:3203: sent IKE msg (P1_RETRANSMIT): 200.195.149.26:500->170.231.15.66:500, len=172, vrf=0, id=ecea911495885ac4/4fea753eb08576f2
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: IPsec SA connect 6 200.195.149.26->170.231.15.66:0
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: using existing connection
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: config found
ike 0:VPN_WINOV_SP: request is on the queue
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: IPsec SA connect 6 200.195.149.26->170.231.15.66:0
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: using existing connection
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: config found
ike 0:VPN_WINOV_SP: request is on the queue
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: IPsec SA connect 6 200.195.149.26->170.231.15.66:0
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: using existing connection
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: config found
ike 0:VPN_WINOV_SP: request is on the queue
ike 0: comes 170.231.15.66:500->200.195.149.26:500,ifindex=6,vrf=0....
ike 0: IKEv1 exchange=Identity Protection id=ecea911495885ac4/0000000000000000 len=172 vrf=0
ike 0: in ECEA911495885AC400000000000000000110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_WINOV_SP:3203: retransmission, re-send last message
ike 0:VPN_WINOV_SP:3203: out ECEA911495885AC44FEA753EB08576F20110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000148299031757A36082C6A621DE000000000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000
ike 0:VPN_WINOV_SP:3203: sent IKE msg (retransmit): 200.195.149.26:500->170.231.15.66:500, len=172, vrf=0, id=ecea911495885ac4/4fea753eb08576f2
ike 0:VPN_WINOV_SP:3203: out ECEA911495885AC44FEA753EB08576F20110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000148299031757A36082C6A621DE000000000D0000144048B7D56EBCE88525E7DE7F00D6C2D3000000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000
ike 0:VPN_WINOV_SP:3203: sent IKE msg (P1_RETRANSMIT): 200.195.149.26:500->170.231.15.66:500, len=172, vrf=0, id=ecea911495885ac4/4fea753eb08576f2
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: IPsec SA connect 6 200.195.149.26->170.231.15.66:0
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: using existing connection
ike 0:VPN_WINOV_SP:VPN_WINOV_SP: config found
ike 0:VPN_WINOV_SP: request is on the queue
ike 0:VPN_WINOV_SP:3201: d3fcd5f5f857c37f/0000000000000000 negotiation of IKE SA failed due to retry timeout
ike 0:VPN_WINOV_SP:3201: expiring IKE SA d3fcd5f5f857c37f/0000000000000000
ike 0:VPN_WINOV_SP: deleting
ike 0:VPN_WINOV_SP: deleted

 

Am I doing something wrong?

10 replies

Anthony_E
Staff
Staff
January 9, 2023

Hello Bruno,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Best Regards
akristof
Staff
Staff
January 10, 2023

Hello,

Based on the debug peer is also FortiGate. Please run the debug on that FortiGate also so we can compare what other peer's seeing. Next step would be packet capture for IKE packets to see if they received, but maybe dropped. Last thing is config. How is the VPN on this device configured. Ping should not affect ability to accept packets for IKE.

Brustolin
BrustolinAuthor
Explorer
January 10, 2023

Hello Adrian,

 

This is the output from the other Fortigate:

 

ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:5848709: c792a644f887907a/0000000000000000 negotiation of IKE SA failed due to retry timeout
ike 0:VPN_MITRA01:5848709: expiring IKE SA c792a644f887907a/0000000000000000
ike 0:VPN_MITRA01: deleting
ike 0:VPN_MITRA01: deleted
ike 0:VPN_MITRA01: schedule auto-negotiate
ike 0:VPN_MITRA01:5848769: initiator: main mode is sending 1st message...
ike 0:VPN_MITRA01:5848769: cookie b91263f394f6ba35/0000000000000000
ike 0:VPN_MITRA01:5848769: out B91263F394F6BA3500000000000000000110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_MITRA01:5848769: sent IKE msg (ident_i1send): 170.231.15.66:500->200.195.149.26:500, len=172, vrf=0, id=b91263f394f6ba35/0000000000000000
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:500 negotiating
ike 0:VPN_MITRA01:5848769:MITRA_172.16.10.0/24:16275951: ISAKMP SA still negotiating, queuing quick-mode request
ike 0:VPN_MITRA01:5848769: out B91263F394F6BA3500000000000000000110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_MITRA01:5848769: sent IKE msg (P1_RETRANSMIT): 170.231.15.66:500->200.195.149.26:500, len=172, vrf=0, id=b91263f394f6ba35/0000000000000000
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:5848769: out B91263F394F6BA3500000000000000000110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_MITRA01:5848769: sent IKE msg (P1_RETRANSMIT): 170.231.15.66:500->200.195.149.26:500, len=172, vrf=0, id=b91263f394f6ba35/0000000000000000
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:5848769: out B91263F394F6BA3500000000000000000110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_MITRA01:5848769: sent IKE msg (P1_RETRANSMIT): 170.231.15.66:500->200.195.149.26:500, len=172, vrf=0, id=b91263f394f6ba35/0000000000000000
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0: cache rebuild done
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0: cache rebuild done
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:5848769: out B91263F394F6BA3500000000000000000110020000000000000000AC0D00003C000000010000000100000030010100010000002801010000800B0001000C00040001518080010007800E00808003000180020002800400050D000014AFCAD71368A1F1C96B8696FC775701000D0000144048B7D56EBCE88525E7DE7F00D6C2D30D0000184048B7D56EBCE88525E7DE7F00D6C2D3C0000000000000148299031757A36082C6A621DE00000000
ike 0:VPN_MITRA01:5848769: sent IKE msg (P1_RETRANSMIT): 170.231.15.66:500->200.195.149.26:500, len=172, vrf=0, id=b91263f394f6ba35/0000000000000000
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: IPsec SA connect 32 170.231.15.66->200.195.149.26:0
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: using existing connection
ike 0:VPN_MITRA01:MITRA_172.16.10.0/24: config found
ike 0:VPN_MITRA01: request is on the queue
ike 0: cache rebuild done

 

The both configs is identicals:

 

edit "VPN_MITRA01"
set interface "WAN"
set local-gw 170.231.15.66
set peertype any
set net-device enable
set proposal aes128-sha1
set negotiate-timeout 300
set comments "Mitra Matriz"
set dhgrp 5
set nattraversal disable
set remote-gw 200.195.149.26
set psksecret ENC xxxxxxxxxxx
next

 

The Fortigates is in 7.2.3 version

 

Thanks

akristof
Staff
Staff
January 11, 2023

Hello,

Sorry for late reply. So in debugs, both sides are retransmitting their packets. Means that at some point, packets are either not delivers or dropped.

I would run debug flow on both devices, like this:

 

diag debug flow filter proto 17

diag debug flow filter port 500

diag debug flow filter addr X.X.X.X - remote IP gateway from local device's perspective

diag debug flow show func en

diag debug flow show iprope en

diag debug console time en

diag debug flow trace start 500

diag debug en

 

Keep it running for couple of seconds if tunnel is always negotiating. Then disable debug:

diag debug disable

 

You can attach files and we can if the packets are received or not and what is happening with them.

Peter-Wainwright
Visitor III
January 12, 2023

I saw a trace very similar to this a few days ago when I was setting up IPsec between two FGT units where one of the ISPs didn't support native ESP over IP. 

Try setting "set nattraversal forced" in the phase1-interface on both sides.

Mahindraholidays
New Member
November 9, 2023

Hi Team 

We are also facing the same issue any solution for this 

Brustolin
BrustolinAuthor
Explorer
November 9, 2023

Hi Mahin,

 

I opened a support ticket and they told me it is not possible get a VPN without secondary addresses on interface.
On the FortiOs 7.4 is possible insert more than 200 IP's in secondary addresses. This solved my problem

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!