FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dwickramasinghe1
Article Id 382297
Description This article describes how to troubleshoot the 'IKE authentication credentials are unacceptable' error on the Windows Native VPN Client when attempting to connect to an IKEv2 IPSEC tunnel on FortiGate
Scope FortiGate, FortiOS, IPSEC, Windows Native VPN Client.
Solution

FortiGate supports Windows Native Client IPSEC connections using IKEv2. FortiGate can use certificate-based authentication to allow the endpoint to connect successfully.

This article assumes that the FortiGate VPN wizard has already been utilized to create an IKEv2 Native VPN tunnel, and the endpoints are correctly configured with the IKEv2 Native VPN settings.

In some cases, it's possible to run into the following error:

Error:
'IKE authentication credentials are unacceptable'


IKEErrorNative.jpg
This error usually occurs when the Windows Device does not trust the IPSEC server certificate due to a missing Certificate Authority in the Windows Store.

 

To resolve this issue, check for the configured IPSEC server certificate under: FortiGate GUI -> VPN -> VPN Tunnels -> Select the desired tunnel and take note of the configured 'signature' name.

IKEV2CertificateLocation.jpg

After verifying the configured IPSEC certificate, navigate to the FortiGate certificate store under: FortiGate GUI -> System -> Certificates > Select the IPSEC server certificate and take note of the 'Issuer' (CA) field.

 

CAcertificateField.jpg
After confirming the CA for the IPSEC server certificate, obtain the CA file and upload the CA file to the Microsoft certificate store on the Windows Endpoint:

CertificateCA.jpg
Once the CA certificate has been uploaded to the Trusted Root Certificate Authorities store, restart the endpoint and attempt the connection again. The connection should succeed after making these changes.

ITworkd!.jpg
Related document:
Windows IKEv2 native VPN with user certificate | FortiGate / FortiOS 7.6.2 | Fortinet Document Libra...