strange ipsec issue
hiho,
I got a strange issue here:
I set up IPSec between two FGT with 6.0.x and one side behind NAT (LTE Box) with success using fortiddns as remote gw.
Now I had to to the same with an older FGT 80C which is behind NAT. Other Side is still a 100E with 6.0.x.
While this worked like out of the box with two FGT on 6.0.x right when the Policies and Routes were set, it refuses to work with remote side on 5.4.
I used the same config on both sides, so I am a 100% sure that my settings,psk, dh-groups and proposals do match. So does the IKE Version. As I said it worked fine between two FGT on 6.0.x.
With one side on 5.4 all I get is "ike Negotiate ISAKMP SA Error: ike 0:d2780712bdf9ea36/0000000000000000:71183: no SA proposal chosen" in ike debug log on the 6.0.x FGT. The other side also reports that no SA proposal was chosen.
I tried several combinations and enabled several dhgroups in p1 as well as in p2 with no success.
Do you have any advice?
