Skip to main content
aurelio_malheiros
New Member
October 28, 2020
Question

VPN IPsec Down (between fortinet and pfsense)

  • October 28, 2020
  • 5 replies
  • 7909 views
I'm trying to close VPN between a fortinet and a pfsense
However, in pfsense the following errors appear:

Pfsense:
IDir 'dmz' does not match to 'ip_public'
vici client 1343 disconnected

Fortinet
proposal id = 0:
ike 0:c92ff0a45a5633a6/0000000000000000:442363:   protocol id = ISAKMP:
ike 0:c92ff0a45a5633a6/0000000000000000:442363:      trans_id = KEY_IKE.
ike 0:c92ff0a45a5633a6/0000000000000000:442363:      encapsulation = IKE/none
ike 0:c92ff0a45a5633a6/0000000000000000:442363:         type=OAKLEY_ENCRYPT_ALG, val=AES_CBC, key-len=256
ike 0:c92ff0a45a5633a6/0000000000000000:442363:         type=OAKLEY_HASH_ALG, val=SHA.
ike 0:c92ff0a45a5633a6/0000000000000000:442363:         type=AUTH_METHOD, val=PRESHARED_KEY.
ike 0:c92ff0a45a5633a6/0000000000000000:442363:         type=OAKLEY_GROUP, val=MODP1024.
ike 0:c92ff0a45a5633a6/0000000000000000:442363: ISAKMP SA lifetime=28800
ike 0:c92ff0a45a5633a6/0000000000000000:442363: negotiation failure

I changed the dh and still has a problem.

    5 replies

    emnoc
    New Member
    October 28, 2020

    Como vc vai? 

     

    So in your pfsense did you match the settings exactly? Also depending on what version of pfense you have, you might need to allow for iskamp and esp. What I would do is to look to see if you are getting data from the pfsense instance

     

    e.g

     

       diag sniffer packet  wan1 "port 500 or 4500 and udp"

     

    Can you do that and report back if the pfsense instance is responding back to the fgt?

     

    Ken Felix

    aurelio_malheiros
    New Member
    October 29, 2020

    Good Morning

    The vpn looks like this on both sides:

     

    Fortinet

    Fase 1

    Enable DPD Delay 10

    Ikev1

    [image][/image]

    Seconds: 3600

     

     

    The

    hostname # diagnose sniffer packet any "host IP_PUBLIC_PFSENSE" interfaces=[any] filters=[host IP_PUBLIC_PFSENSE] 1.228707 IP_PUBLIC_DMZ_FORTINET.4500 -> IP_PUBLIC_PFSENSE.4500: udp 104 13.228702 IP_PUBLIC_DMZ_FORTINET.4500 -> IP_PUBLIC_PFSENSE.4500: udp 104 22.968984 IP_PUBLIC_DMZ_FORTINET.500 -> IP_PUBLIC_PFSENSE.500: udp 304 23.412013 IP_PUBLIC_PFSENSE.500 -> IP_PUBLIC_DMZ_FORTINET.500: udp 156

     

    I will try to do this procedure: allow for iskamp and esp

    emnoc
    New Member
    October 29, 2020

    Ola,  tem um problema ;)

     

    So it  looks like NAT-T is required have you confirmed NAT-T is enabled? It should be on forti0s by default but on pfsense you might have to enable the checkbox iirc for NAT-T.

     

     

    Ken Felix

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!