Skip to main content
domisawadogo
New Member
April 19, 2018
Question

VPN Progress IPsec phase 2 ISSU

  • April 19, 2018
  • 2 replies
  • 11085 views

My VPN is UP. but at the log level I have a mistake   Progress IPsec phase 2 Action negotiate Status failure Result ERROR

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    April 19, 2018

    You need to provide enough info for anyone to understand what your VPN is. Site-to-site or remote access? Do you have multiple phase2s or just one? What is the selectors in phase2s? copy&paste&mask-some-IDs of phase1-interface and phase2-interface into the thread is the best.

    domisawadogo
    New Member
    April 19, 2018

    it is a VPN SITE to SITE with two phase. It's between fortigate-cisco how much of a phase should I do?

    Toshi_Esumi
    SuperUser
    SuperUser
    April 19, 2018

    IPSec (w/ IKEv1) always have two phases, phase1 and phase2. I was asking if you have muiltpke phase2-interfaces configured to have multiple traffic selectors. The default is 0/0 <-> 0/0 means all. If you go to "config vpn ipsec phase2-interface" in CLI then "show" would show you all phase2s you configured.

    And you said "UP", but is it actually passing traffic site-to-site?

    domisawadogo
    New Member
    April 19, 2018

    the tunnel goes to UP. but I have an error for phase two

     

    ActionnegotiateStatusfailureResultERROR