Description | This article describes how to fix where the VPN debug does not show any VPN proposal. It only shows FortiGate proposals. |
Scope | FortiGate v7.0.12 or above. |
Solution |
ike 0::57: peer identifier IPV4_ADDR 192.168.1.9 ike 0: IKEv1 Aggressive, comes 152.203.102.115:500->10.1.0.16 3 ike 0:99e90a0d7e6f491e/0000000000000000:57: my proposal, gw Test: ike 0:99e90a0d7e6f491e/0000000000000000:57: proposal id = 1: ike 0:99e90a0d7e6f491e/0000000000000000:57: protocol id = ISAKMP: ike 0:99e90a0d7e6f491e/0000000000000000:57: trans_id = KEY_IKE. ike 0:99e90a0d7e6f491e/0000000000000000:57: encapsulation = IKE/none ike 0:99e90a0d7e6f491e/0000000000000000:57: ike 0:99e90a0d7e6f491e/0000000000000000:57: ISAKMP SA lifetime=86400 ike 0:99e90a0d7e6f491e/0000000000000000:57: negotiation failure ike Negotiate ISAKMP SA Error: ike 0:99e90a0d7e6f491e/0000000000000000:57: no SA proposal chosen
config vpn ipsec phase1-interface end |