Created on
‎05-19-2025
01:03 AM
Edited on
‎06-20-2025
04:37 AM
By
Anthony_E
Description |
This article describes a scenario where an IPsec Dial Up Tunnel is configured in the FortiGate using the IPsec Wizard Template, and while connecting to the IPsec Dial Up VPN from the FortiClient, getting 'Timeout while connecting to <remote_gateway_ip>' error, and unable to connect to the VPN: |
Scope | FortiGate, FortiClient. |
Solution |
When the IPsec Dial Up Tunnel is configured from the IPsec Wizard Template, edit the IPsec Tunnel Configuration and select 'convert to custom tunnel' to view the phase 1 and phase 2 selectors of the Dialup Tunnel.
By default, in FortiGate, the Diffie-Hellman Groups are 14 and 5 in both phase 1 and phase 2 selectors of the Tunnel settings.
But whereas in the FortiClient, by default, the Diffie-Hellman Group is 20 in both phase 1 and phase 2 selectors.
As there is a mismatch between the DH groups in FortiClient and the FortiGate, the user cannot connect to the IPsec Dial Up VPN, and a timeout error is received.
Packet capture with the user's public IP can be used to verify the SA proposal sent by the FortiClient. If it does not match with any SA proposal configured on FortiGate, it will show a timeout error.
There could be other reasons for the timeout error as well; this can be verified with an IKE debug. In case of no proposals accepted, the following error can be seen in the IKE debug:
2025-06-12 10:51:23.687782 ike 0:Test-Office:29: sent IKE msg (P1_RETRANSMIT): 172.16.207.2:500->172.18.82.167:500, len=572, vrf=0, id=3e0fbb0e7d5ec20e/0000000000000000
If the issue persists, IKE debug can be collected to investigate the issue: Troubleshooting Tip: IPsec VPN tunnels |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.