Skip to main content
sw2090
SuperUser
SuperUser
October 25, 2024
Question

strange behavior on ipsec vpn

  • October 25, 2024
  • 1 reply
  • 1157 views

Following constellation:

 

FortiGate with FOS 7.2.10

FortiClient 7.2.5 on windows.

 

IPsec tunnel witb psk and xauth against ldap usergroup on Authenticator and mode config.

 

Behavior:

- Tunnel connects

- does psk auth and proposals

- does mode config - gets ip and everything

- initates xauth

- fgt send xauth request to client

 

Log on FGT reports "Client has not completet xauth challenge" even before the forticlient prompts me for 2nd factor.

Looks like FGT sends the xauth request but does not wait for an answer from client.

 

Do you have any suggestions?

1 reply

abarushka
Staff
Staff
October 25, 2024

Hello,

 

I would recommend to collect debug traces below while the issue is reproduced:

 

diagnose debug application fnbamd -1
diagnose debug application ike -1
diagnose debug enable

 

Moreover, I would also recommend to check FortiClient logs.