Problem with IPSEC L2L betewen Fortigate and a Cisco ASR
Hi everyone, at this moment i have some problem with my tunnel ipsec betewen my Fortgate and a Router Cisco ASR.
My fortigate is running 5.2.7 version.
what i see so far, all configuration phase 1 and phase 2 its correct. When the peer remote try to estabilsh this tunel, this happen with sucess, but, if i force my fortigate to estabilsh this tunnel i got this error;
here is the log that i believe is the phase 1 OK;
ike 2:L2L-XXXXX-02:1401224921: peer identifier IPV4_ADDR 1.1.1.1 ike 2:L2L-XXXXX-02:1401224921: PSK authentication succeeded ike 2:L2L-XXXXX-02:1401224921: authentication OK ike 2:L2L-XXXXX-02:1401224921: established IKE SA f3dae8bfc4e9daf8/8099b52c50adf6a6 ike 2:L2L-XXXXX-02: HA send IKE connection add 2.2.2.2->1.1.1.1 ike 2:L2L-XXXXX-02:1401224921: HA send IKE SA add f3dae8bfc4e9daf8/8099b52c50adf6a6 ike 2:L2L-XXXXX-02: set oper up ike 2:L2L-XXXXX-02: schedule auto-negotiate ike 2:L2L-XXXXX-02:1401224921: no pending Quick-Mode negotiations
then i try to ping the ip address that i have in my phase 2 and i got this error;
ike 2:L2L-XXXXX-02:1401257287: notify msg received: NO-PROPOSAL-CHOSEN
but, like i sad early, if the peer remote try to estabilsh this tunnel, i got the status UP phase 1 and phase 2 and i can ping the other side, but i really need the fortigate to estabilish this and i dont know where is the error...
anyone have face a error like this before??
