Skip to main content
vinceneil666
New Member
April 9, 2018
Question

VPN, phase one stuck.

  • April 9, 2018
  • 2 replies
  • 43651 views

hi all.

I have two Fortigates running 5.2 and 5.4 - the 5.4 (30E) is behind a NAT device - thus nat'ing its outbound traffic.

 

For some reason I am unable to get this vpn up n runnin. I have been trough all of google allready :) .. The thing is I keep getting this on the 5.2 (thats the device I am connecting to)

 

ke 2: cache dirty, wait for rebuild ike 2:1995709eec1ddf64/0000000000000000:13895: incoming proposal: ike 2:1995709eec1ddf64/0000000000000000:13895: proposal id = 0: ike 2:1995709eec1ddf64/0000000000000000:13895: protocol id = ISAKMP: ike 2:1995709eec1ddf64/0000000000000000:13895: trans_id = KEY_IKE. ike 2:1995709eec1ddf64/0000000000000000:13895: encapsulation = IKE/none ike 2:1995709eec1ddf64/0000000000000000:13895: type=OAKLEY_ENCRYPT_ALG, val=3DES_CBC. ike 2:1995709eec1ddf64/0000000000000000:13895: type=OAKLEY_HASH_ALG, val=SHA. ike 2:1995709eec1ddf64/0000000000000000:13895: type=AUTH_METHOD, val=PRESHARED_KEY. ike 2:1995709eec1ddf64/0000000000000000:13895: type=OAKLEY_GROUP, val=MODP1024. ike 2:1995709eec1ddf64/0000000000000000:13895: ISAKMP SA lifetime=25000 ike 2:1995709eec1ddf64/0000000000000000:13895: negotiation failure ike Negotiate ISAKMP SA Error: ike 2:1995709eec1ddf64/0000000000000000:13895: no SA proposal chosen

 

And thats pretty much it.. I have tried tuning all kinds - but no way... I have made sure my policy is ok for traffik, NAT-t . routing.. PSK is checked and checked again, and again. I have made very - very - sure that proposals match on both phase1 and phase 2... and now I am stuck.

 

Note that I need to have this running over NAT, its not an option to not have this in place...

 

anyone ? :)

    2 replies

    kurtli_FTNT
    Staff
    Staff
    April 9, 2018

    Hi there,

        Have you enable "NAT-traversal" on each site?

     

     

     

    Thanks

     

    vinceneil666
    New Member
    April 9, 2018

    Yep!

    emnoc
    New Member
    April 9, 2018

    check for;

     

    IKEv1 vrs IKEv2 mismach

     

    3DES-SHA mismatch w/DHGRP 2

     

     

    FWIW: if you use IKEv2, NAT-T is built in ;)

     

     

    kumaran
    New Member
    April 11, 2018

    COULD YOU PLEASE CHECK BY DISABLING THE NAT TRAVERSAL IN THE INITIATER END ( THAT IS SUBNET GETTING NATTED INBETWEEN)

     

    I THINK THIS WILL SOLVE YOUR ISSUE.

     

    vinceneil666
    New Member
    April 12, 2018

    Nope - :( That didnt work.

     

    kurtli_FTNT
    Staff
    Staff
    April 12, 2018

    "As of now I am testing with just setting the static ip of my 30E (the NAT address of the 200).. but still no go."

    --Is this a 1v1 NAT in 200D? Try to add fixed port in firewall policy on 200D and then give a try on using/not using nat-t on both ends. Don't forget now the remote-gw on 90D to the NATed IP. If still no luck, post the output of 'diag debug application ike -1'