Skip to main content
Fortiben1
Explorer II
March 7, 2025
Question

Negotiate and Success

  • March 7, 2025
  • 1 reply
  • 502 views

Hi People!,

 

I just want to ask regarding the IPsec VPN logs. We found a malicious remote IP address in our logs. I want to ask what the status = Success and 1 is negotiate_error, and the message = progress IPsec phase 2 and IPsec phase 1 SA mean. Does this indicate that the malicious IP has successfully penetrated? What are the possible troubleshooting steps or solutions to stop this?

 

Thank you! 

1 reply

AEK
SuperUser
SuperUser
March 8, 2025

Hi Ben

I guess this is a dial-up IPsec.

 

Does this indicate that the malicious IP has successfully penetrated?

-> I think if he managed to connect successfully then you should see a message like "Tunnel up" and clearly identify the username. Or at lease you may check the traffic logs to see if there was any suspicious traffic.

 

Regarding your last question, I'd use 2FA for better security (password + token or mail OTP).

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.