Description |
This article describes the issue where VPN phase 1 is not coming up for a route-based VPN and the debug logs are showing the message: 'ignoring request to establish IPsec SA, gateway is in passive mode'. |
Scope | FortiGate 6.2, 6.4, 7.0, 7.2. |
Solution |
Disable passive mode in VPN phase 1 setting. Follow the steps given below:
# config vpn ipsec phase1-interface This setting makes the FortiGate a Responder and will ignore any IKE request if it is being initiated by the FortiGate. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.