Description | This article explains how to fix a phase1 issue about 'error constructing ID payload'. |
Scope | FortiGate. |
Solution |
When establishing IPSEC VPN site to site with a peer device using IKEv2, the below error can be seen in IKE debugs during the authentication process:
2024-09-20 18:20:22.440112 ike V=root:0:FGT-VPN:13258: initiator preparing AUTH msg
After making sure proposals, key lifetime and other phase1 parameters match and are compatible with the VPN peers, check the VPN phase1 config with the next command: 'show vpn ipsec phase1-interface'. If noticing the 'localid-type' is set under the tunnel name with the issue as below: config vpn ipsec phase1-interface
config vpn ipsec phase1-interface
After making the changes, the tunnel should come up without ID type mismatch and the error in question. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.