Description | This article describes that a restrictive Password Policy can cause issues during the FortiExtender (FEX) setup/configuration on the FortiGate. FortiGate has a predefined password policy for generating a preshared key for the FortiExtender IPsec. If the FortiExtender IPsec preshared key is not comforting the password policy, the IPsec tunnel interface won't be created. |
Scope | Password Policy, FortiExtender (FEX), FortiGate. |
Solution |
When configuring FortiExtender on the FortiGate, FortiGate automatically creates the IPsec tunnel for FortiExtender. The IPsec tunnel preshared key FortiGate generates has a predefined length of 16 alphanumeric characters (a-z A-Z 0-9), without special characters. If there is a Password Policy configured on FortiGate:
GUI: Go to System -> Settings -> Password Policy.
CLI:
* *
This Password Policy is restrictive enough so IPsec FortiExtender preshared key does not meet its requirements, and IPsec will not be created.
The output of the 'diagnose debug cli 8' debug command during the FortiExtender configuration on FortiGate shows the following:
2024-07-11 10:26:18 cmd=config vpn ipsec phase1-interface
Error code -49 is:
If this issue happens, there are two possible approaches to overcome it:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.