Skip to main content
jomof
New Member
December 23, 2024
Solved

Not seeing the option configure to AES and sha 256 on FortiGate hub using ADVPN

  • December 23, 2024
  • 8 replies
  • 2782 views

Hello all,

 

I humbly request your assistant.

 

I configure the ADVPN on the hub but I would like to configure AES and sha 256 but I am not allowed to configure same .

 

The screen shot below is only options I am see, not even the option to convert to full configure is displayed.

Screenshot 2024-12-23 082946.png

 

Thank you

 

Regards

 

Best answer by kaman

Hi jomof,

For Hub-and-Spoke template there is no option to edit through GUI.

You can edit from the CLI as below:

config vpn ipsec phase1-interface
edit star_lethem
set proposal aes128-sha256
end

You can use the "?" keyword also after set proposal command to check all the Phase1 proposals.

If you have found a solution, please like and accept it to make it easily accessible to others.

Regards,
Aman

8 replies

kaman
Staff
Staff
December 23, 2024

Hi @jomof,

You can see the Encryption and Authentication settings under Phase1 Proposal

Also, when users create an IPSec VPN using the VPN Creating Wizard, it is impossible to view the phase 1/phase2 proposals and IKE version in the GUI, select 'Convert To Custom Tunnel' to view and modify the settings in the GUI.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Change-in-default-settings-when-creating-IPSec/ta-p/346695

If you have found a solution, please like and accept it to make it easily accessible to others.

Regards,
Aman




jomof
jomofAuthor
New Member
December 23, 2024

Hello Kaman,

Thank you for the prompt reply 

I am not seeing the convert to custom tunnel option. 

 

Screenshot 2024-12-23 095117.png

Renante_Era
Staff
Staff
December 23, 2024

It appears that it's already converted to custom. You should be able Phase1 and Phase2 entries by selecting the pen like icon.

If you want to edit that in CLI, you'll be able to see the settings using the following commands:

show full vpn ipsec phase1-interface

show full vpn ipsec phase2-interface

kaman
Staff
Staff
December 23, 2024

Please refer to the below document on IPsec VPN wizard hub-and-spoke ADVPN support


https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/853412/ipsec-vpn-wizard-hub-and-spoke-advpn-support

jomof
jomofAuthor
New Member
December 23, 2024

Hello Kaman,

 

I redo the hub using the information from the document but still not getting the option Convert to Custom Tunnel.

 

Regards

hbac
Staff
Staff
December 23, 2024

Hello @jomof,

 

Have you tried making those changes in the CLI? 

 

Regards, 

kaman
Staff
kamanAnswer
Staff
December 24, 2024

Hi jomof,

For Hub-and-Spoke template there is no option to edit through GUI.

You can edit from the CLI as below:

config vpn ipsec phase1-interface
edit star_lethem
set proposal aes128-sha256
end

You can use the "?" keyword also after set proposal command to check all the Phase1 proposals.

If you have found a solution, please like and accept it to make it easily accessible to others.

Regards,
Aman

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!