Site-to-Site VPN not Working on FortiGate to ASA 5505
- March 21, 2018
- 6 replies
- 28048 views
I'm trying to configure IPsec VPN on a Fortigate 80C, and on a Cisco ASA 5505 firewall. Fortigate 80C is running v4.0, build0646, and Cisco ASA 5505 is running 8.2(5), with ASDM 7.12.
I configured Site-to-Site on ASA and assigned a peer IP address of the FortiGate unit. I assigned a pre-shared key as well. ASA and FortiGate, both have matching pre-shared keys and identical phase 1 and phase 2 settings.
When I log into FortiGate using web interface, I go to Log & Report and click on Event Log. For Action I see negotiate with a message saying IPsec phase 1 error, and Error Reason no matching gateway for new request. It has ID 37124.
ASA can ping outside WAN IP 172.16.1.6, ASA can also ping IP 192.168.131.77 located inside its LAN network.
FortiGate can ping outside ASA IP 172.16.1.3, and it's internal LAN of IP 192.168.161.7.
My goal is to be able to ping from FortiGate internal IP 192.168.161.7 to ASA's internal IP 192.168.131.77.
Any help is greatly appreciated. I'm willing to post ASA running config, or anything requested to help make VPN work. Thank you for your time.
