Skip to main content
SidiMamoun
New Member
April 11, 2023
Question

VPN Site to Site expired due to phase 1 down

  • April 11, 2023
  • 4 replies
  • 6170 views

Hello,

I have a problem with establishing a site to site VPN, we have fortigate 60E on our side and cisco ASA on partners side.

You'll find bellow the results of the debug:

2023-04-11 04:56:12.586859 ike 0:VPN-X:10634: out 7C4EE6958EB809940000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500007B8DC496C30E865C1796B8CAF210EB69BB3D59EBE2874CDAF4792857CA7B126D9038879AD02D883D3065C9771AE40D47429296C68E7CEF147BB00EE2B0CDA28C1981DD318990E91121329743D4B5464716E8C288CCDDA5CE6D031E2F29C742EBDBB3FB70DFD9C1EACAF7002F9FB8C52085A83D10076826C0E1047C93EEB9255DB9DC91963B18B921E8602C785E908E2B223A713265CCBBF1A9633CD3B8260EBFF71A7A83AE96079D61C0E18ED4AE531213456D97E785BA948874D024E12A71DB29000014F9300D4BEE615BF91D43479DF27CC3082900001C00004004FA471070E89A907177FAAE1E9AAA8B9320649CD70000001C0000400566197531D175933B8640C0E6AE2033C179E31A60

2023-04-11 04:56:12.587079 ike 0:VPN-X:10634: sent IKE msg (RETRANSMIT_SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=7c4ee6958eb80994/0000000000000000

2023-04-11 04:56:15.576877 ike shrank heap by 122880 bytes

2023-04-11 04:56:24.596856 ike 0:VPN-X:10634: out 7C4EE6958EB809940000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500007B8DC496C30E865C1796B8CAF210EB69BB3D59EBE2874CDAF4792857CA7B126D9038879AD02D883D3065C9771AE40D47429296C68E7CEF147BB00EE2B0CDA28C1981DD318990E91121329743D4B5464716E8C288CCDDA5CE6D031E2F29C742EBDBB3FB70DFD9C1EACAF7002F9FB8C52085A83D10076826C0E1047C93EEB9255DB9DC91963B18B921E8602C785E908E2B223A713265CCBBF1A9633CD3B8260EBFF71A7A83AE96079D61C0E18ED4AE531213456D97E785BA948874D024E12A71DB29000014F9300D4BEE615BF91D43479DF27CC3082900001C00004004FA471070E89A907177FAAE1E9AAA8B9320649CD70000001C0000400566197531D175933B8640C0E6AE2033C179E31A60

2023-04-11 04:56:24.597050 ike 0:VPN-X:10634: sent IKE msg (RETRANSMIT_SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=7c4ee6958eb80994/0000000000000000

2023-04-11 04:56:36.586845 ike 0:VPN-X:10634: negotiation timeout, deleting

2023-04-11 04:56:36.589409 ike 0:VPN-X: connection expiring due to phase1 down

2023-04-11 04:56:36.589449 ike 0:VPN-X: deleting

2023-04-11 04:56:36.589471 ike 0:VPN-X: flushing

2023-04-11 04:56:36.589651 ike 0:VPN-X: flushed

2023-04-11 04:56:36.589714 ike 0:VPN-X: deleted

2023-04-11 04:56:36.589741 ike 0:VPN-X: schedule auto-negotiate

2023-04-11 04:56:37.596860 ike 0:VPN-X:VPN-X: chosen to populate IKE_SA traffic-selectors

2023-04-11 04:56:37.596980 ike 0:VPN-X: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation

2023-04-11 04:56:37.597104 ike 0:VPN-X:10635: out 85856F5AECE46AF50000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500000211016973BEEE810A1B1F71EC27D38C5BA0D57965A1A96261535D9F47A9FDEF82FEF40E0FAD754F9D4902A6E5C6E931A3CDCAB271784D3B6DC96D3DE2F6DC82DF1125E6C177517E2EEA7AD8CB7293A352D24DABE53BA59F52F32CDE78838BB46931D5A482DE21075AE67A935BD5F9AFA63B80650F4E25AF264A1A836D19A68E6801D172BC8B7AC542F691480886239909E5ED122DC4178AC0DF033233AD8868A95E4E7B6670B3E78DBD1F0F2F47C5D033B800E8325AEEEDEAD931FD9FC355A729000014AA392F42722E8928FCBB60E98FA6D2AF2900001C00004004F14FD9F49EDF9D86D7F4021DA302B06AF81640E80000001C0000400527DD2E55E4AA827CD6A87CA6CCC89355346B4718

2023-04-11 04:56:37.597302 ike 0:VPN-X:10635: sent IKE msg (SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=85856f5aece46af5/0000000000000000

2023-04-11 04:56:43.606883 ike 0:VPN-X:10635: out 85856F5AECE46AF50000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500000211016973BEEE810A1B1F71EC27D38C5BA0D57965A1A96261535D9F47A9FDEF82FEF40E0FAD754F9D4902A6E5C6E931A3CDCAB271784D3B6DC96D3DE2F6DC82DF1125E6C177517E2EEA7AD8CB7293A352D24DABE53BA59F52F32CDE78838BB46931D5A482DE21075AE67A935BD5F9AFA63B80650F4E25AF264A1A836D19A68E6801D172BC8B7AC542F691480886239909E5ED122DC4178AC0DF033233AD8868A95E4E7B6670B3E78DBD1F0F2F47C5D033B800E8325AEEEDEAD931FD9FC355A729000014AA392F42722E8928FCBB60E98FA6D2AF2900001C00004004F14FD9F49EDF9D86D7F4021DA302B06AF81640E80000001C0000400527DD2E55E4AA827CD6A87CA6CCC89355346B4718

 

 

Can you please help.

 

4 replies

abarushka
Staff
Staff
April 12, 2023

Hello,

 

There is an error message below:

2023-04-11 04:56:37.596980 ike 0:VPN-ATS: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation

 

I would recommend to check whether phase1 configuration is matching on IPsec peers and remote gateways are correct.

SidiMamoun
New Member
April 13, 2023

Hello,

 

We've made sure it's the same configuration.

Could it be because we're using 2 different firewalls?

 

Best regards,

rtichkule
Staff
Staff
April 14, 2023

Hello,

 

Fortigate supports the VPN connection with the Cisco ASA, in the VPN creation wizard you have the option to select the remote device type Cisco.

 

Although you cross-checked and found that the setup is the same, the debug logs indicate that IKE SA is not matching. For testing purposes, you can try using the remote device as Cisco in the VPN creation wizard to create a new tunnel.

 

BR

Rakesh

rosatechnocrat
Explorer III
April 12, 2023

Yeah .. seems issue is because wrong phase 1 parameters. Please verify the phase1 settings at both end. 

 

no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation

 

 

Subscribe "ROSA Technocrat" on Youtube for Fortinet Videos and Troubleshooting https://www.youtube.com/@rosatechnocrat
Christian_89
Contributor III
April 16, 2023

in phase 1 is a wrong parameter as I have already been informed.

mgoswami
Staff
Staff
April 17, 2023

Hi,

 

Can you please check phase1 settings on both side of tunnels. Based on debugs, it seems there's a mismatch in phase1 settings.

ref output:

2023-04-11 04:56:37.596860 ike 0:VPN-X:VPN-X: chosen to populate IKE_SA traffic-selectors

2023-04-11 04:56:37.596980 ike 0:VPN-X: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation

 

Also, please check if DPD is enabled on both the ends.