Created on 08-31-2023 08:39 AM Edited on 06-11-2024 09:52 PM By Anthony_E
Description | This article describes the possible reasons that the IPsec tunnel via ikev2 fails, usually, this issue happens when the third-party device is acting as a responder in the IPsec tunnel. |
Scope | FortiGate. |
Solution
|
In IKEv2, IKE AUTH (authentication) takes place after the SA_INIT exchange, initiator sending an AUTH message to the other side mainly for authentication purposes.
Here are partial IKE negotiation logs between FortiGate and Zscaler that show the remote side is rejecting authentication messages sent by the FortiGate side:
ikee 0:IPSECVPN_Zscaler:1094499: IKE SA 65d3ae182a9bf8e4/53cd353c74a2861e SK_ar 32:20171069004658BE6262ADCA4DC83BEAFDD30075C6AD5632804A0863523C26E4 65D3AE182A9BF8E453CD353C74A2861E2E20230800000001000000D8230000BC856A01C42BA44075D88F5E70549ED2EEC749348587C4305BB4B7B506D58BE5D48EB8AFFA6A67ED30E393BEAA1D4D03D3A5F7C327C24024E6BA1CB380B5BDD763838383FEC5DBA5FC26316DF03A70C873BF303A02AB033026C8AB88625DF1C8518D15B8387A0EAFFA94E00128CCCEE028CA3BB7BBF80E0ACFB725F1AD0F7D6A283FECE39F4D7695A912DC32D4F5B483BD426D60F31EAAAAEF69B513B9ABBC2C30E69E39F8938D8F43E6B29FE991ABD59A162AF1C927252BD7
Note: The AUTH message is protected by the cryptographic algorithms and the keys from the SA_INIT message.
Generally, 'malformed message' error describes that there is a mismatch, possible reasons that the remote side might reject the AUTH message as responder are as follows and the remote side should be checked:
Related article: Technical Tip: IPsec VPN error 'ike Negotiate SA Error: ike ike [1470]'. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.