VPN Tunnel (Tunnelmode) between two Fortigates up , but can only one ping side
Hi all,
In one of our branch offices we had to replace one of our Fortigates for a new one. After setup the Fortigate the tunnel came up (Fortige 60D - Fortigate 60B) and everything looks ok. Now it looks like we can ping from HQ - to the branch , but when we want to ping from branch to HQ it failed. When we do a trace on the Branch FG to HQ it's not going to HQ but to the internet. The firewall looks like correct , so that's not the problem.
When i go to the VPN logs i get a error on phase1 with reason: peer SA proposal not match local policy
That's strange because both sides are the same except IKE version 1 or 2 is not selectable on the HQ FG , because that's an older version.
Anyone suggestions or ideas?
