Created on 09-14-2022 02:24 PM Edited on 09-14-2022 02:25 PM By Anonymous
Description |
This article describes an IPSec scenario with error ‘error calculating auth information’ in IKE debug logs
In this scenario, the IPsec tunnel is configured between FortiGate and FortiGate/non-Fortinet peer, with appropriate phase1 and phase2 configuration on respective nodes, the phase 2 remains down. In IKE debug logs, it can be seen that phase1 negotiation is successful, in phase 2, the negotiation stops when the responder is unable to process the authentication message sent by the initiator.
After the responder fails to calculate authentication information, the initiator or peer will try to send authentication information periodically and phase2 will remain down.
This error message can appear when either using IKEv1 or IKEv2. |
Scope | FortiGate 7.0 and above |
Solution |
Make sure that the P1 interface had localid-type set to ‘auto’ instead of ‘key-id’. In the previous configuration, localid-type is set as keyed but no string value is assigned to the ‘set localid <IP string>’ command. Either users can unset the localid option or manually set it to ‘auto’. This will ensure that the phase2 is successfully negotiated.
Before:
# config vpn ipsec phase1-interface
After:
# config vpn ipsec phase1-interface
Related KB articles:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/649957/phase-1-configuration |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.