Skip to main content
Contributor III
March 14, 2006
Question

NO_PROPOSAL_CHOSEN

  • March 14, 2006
  • 3 replies
  • 2723 views
Hi, I' m trying to connect a forticlient v. 2.0.1.148 on a fortigate 50a 2.8 build489 when I do a test : Negotiate SA Error protocol_id=1, notify_msg=14 (NO_PROPOSAL_CHOSEN), ispi_size=0 any ideas?

    3 replies

    Contributor III
    March 15, 2006
    check your phase1 settings (proposed algorithms should be equal to the ones on the client) (you propably already checked this). What I experienced was that I was able to connect, but another fellow couldn' t, even if he used " my" VIP. If he imported my policy, first then he was able to connect through vpn. All the settings were identical... forticlient is just pure magic.
    Contributor III
    March 16, 2006
    Thanks, phase 1 is ok now, I had to add proposal 2 in each phase. I have tried on two diff. laptops with two diff. vpn clients @home and @work, but it still doesn' t work. Maybe a problem with my fortigate config.... This is the log error I get for my vpn client on my laptop: SENDING>>>> ISAKMP OAK QM *(HASH, SA, NON, KE, ID 2x) RECEIVED<<< ISAKMP OAK INFO *(HASH, NOTIFY:INVALID_ID_INFO) Is it a ip address problème? A pre-shared key problem? Thank you in advance :)
    Contributor III
    March 16, 2006
    are you using a licenced version of forticlient? phase 1 and phase 2 must be similar at the client and the fortigate. The evaluation version of the client doesn' t support 3DES or AES, only DES... the hashing must me the same, if the fgt is configured with sha-1, so should the client.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!