Description |
This article describes an issue where a VPN user is unable to connect Dial-up IPsec VPN with the FortiClient version (7.X.) as the dial-up client when multiple Diffie-Hellman groups are selected.
The ike phase-1 negotiated with SA proposal chosen, but timeout with 'ike 0:<tunnel>:<xx>: parse error ' error.
The ike debug output is shown below:
ike 0:eeb4c223b2101232/0000000000000000:27: SA proposal chosen, matched gateway Dialup |
Scope | FortiGate and FortiClient 7.0 and above. |
This is because FortiClient cannot support multiple phase1 Diffie-Hellman (DH) groups for aggressive mode. Make sure FortiClient uses only one Diffie-Hellman (DH) group with VPN phase 1 aggressive mode configuration. For example:
FortiGate CLI: Dialup IPSEC VPN is configured to accept Diffie-Hellman (DH) groups 5 and 14 in phase 1 interface configurations.
config vpn ipsec phase1-interface set dhgrp 14 5 <-- FortiGate GUI:
FortiClient: Edit VPN Connection -> Advanced Settings -> Phase 1 -> DH Group -> Select only one DH group 14 or 5 to match.
It is strictly recommended to use the same parameters on FortiGate and FortiClient. It does not matter if the SA is negotiated: if some parameters do not match, they may cause parse errors and prevent the negotiation from being established:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.