Skip to main content
nachoju
New Member
September 5, 2017
Question

Peer SA proposal not match local policy - FORTI 100E - AZURE

  • September 5, 2017
  • 6 replies
  • 140909 views

Hi all,

I am having some problems with the Vpn to Azure. I receive this message each 5 minutes from the fortigate. VPN seems to be up but some services fails and I have to bring it down and bring it up again to continue working.

 

Can any one help me? I am new with fortigate.

Thank you in advance.

 

 

Messages:

Message meets Alert condition

date=2017-09-05 time=12:22:01 devname=FG100E-**** devid=FG100E4Q17000357 logid="0101037189" type="event" subtype="vpn" level="error" vd="root" logdesc="IPsec phase 2 error" msg="IPsec phase 2 error" action="negotiate" remip=**** locip=**** remport=500 locport=500 outintf="ppp1" cookies="9213e89c8037d2c6/de8a50a6809f7c00" user="N/A" group="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="VPN_Azure" status="negotiate_error" reason="peer SA proposal not match local policy"

 

Message meets Alert condition

date=2017-09-05 time=12:20:01 devname=FG100E-**** devid=FG100E4Q17000357 logid="0101037189" type="event" subtype="vpn" level="error" vd="root" logdesc="IPsec phase 2 error" msg="IPsec phase 2 error" action="negotiate" remip=**** locip=**** remport=500 locport=500 outintf="ppp1" cookies="9213e89c8037d2c6/de8a50a6809f7c00" user="N/A" group="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="VPN_Azure" status="negotiate_error" reason="peer SA proposal not match local policy" 

 

 

    6 replies

    Agent_1994
    New Member
    September 5, 2017

    I assume that you verified that the FG phase 2 matches Azure.

    Did you try this?

     

    diagnose debug enable diagnose debug application ike -1

    It's output should help

     

    nachoju
    nachojuAuthor
    New Member
    September 6, 2017

    thank you for your suggestions. I have reset the router and now i stopped from receiving this messages and now it seems to be ok. 

     

    Probably the router was filtering anything on 500/4500 ports. 

     

    thank you!!

    yannick22
    New Member
    September 7, 2020

    Had same problem. Did run "diagnose vpn ike restart" which fixed it.

     

    FortiGate 100E v5.4.12,build8180 (GA)

    Allan_Lago
    New Member
    September 5, 2017

    Hi,

     

    Please review your phase 1 and phase 2 proposal configuration on both sites.

     

    They have to match the same encryption and authetication settings on both sides.

     

    Regards,

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!