Created on
09-14-2022
02:24 PM
Edited on
12-24-2025
10:12 AM
By
Stephen_G
| Description |
This article describes an IPSec scenario with error ‘error calculating auth information’ in IKE debug logs
In this scenario, the IPsec tunnel is configured between FortiGate and FortiGate/non-Fortinet peer, with appropriate phase1 and phase2 configuration on respective nodes, the phase 2 remains down. In IKE debug logs, it can be seen that phase1 negotiation is successful, in phase 2, the negotiation stops when the responder is unable to process the authentication message sent by the initiator.
After the responder fails to calculate authentication information, the initiator or peer will try to send authentication information periodically and phase2 will remain down.
This error message can appear when either using IKEv1 or IKEv2. |
| Scope | FortiGate 7.0 and above. |
| Solution |
Make sure that the P1 interface had localid-type set to ‘auto’ instead of ‘key-id’. In the previous configuration, localid-type is set as keyed but no string value is assigned to the ‘set localid <IP string>’ command. Either users can unset the localid option or manually set it to ‘auto’. This will ensure that the phase2 is successfully negotiated.
Before:
config vpn ipsec phase1-interface edit "To_Initiator"
After:
config vpn ipsec phase1-interface edit "To_Initiator" end
Related documents: Troubleshooting Tip: IPsec Tunnel (debugging IKE)Technical Tip: Use of PeerID and LocalID in IPsec VPN between two FortiGates IPsec Phase 1 configurationTroubleshooting Tip: Troubleshooting IPsec site-to-site tunnel connectivity |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.