Created on
08-31-2023
08:39 AM
Edited on
02-09-2025
10:33 PM
By
Anthony_E
Description | This article describes the possible reasons that the IPsec tunnel via ikev2 fails, usually, this issue happens when the third-party device is acting as a responder in the IPsec tunnel. |
Scope | FortiGate. |
Solution
|
In IKEv2, IKE AUTH (authentication) takes place after the SA_INIT exchange, initiator sending an AUTH message to the other side mainly for authentication purposes.
Here are partial IKE negotiation logs between FortiGate and Zscaler that show the remote side is rejecting authentication messages sent by the FortiGate side:
ikee 0:IPSECVPN_Zscaler:1094499: IKE SA 65d3ae182a9bf8e4/53cd353c74a2861e SK_ar 32:20171069004658BE6262ADCA4DC83BEAFDD30075C6AD5632804A0863523C26E4 65D3AE182A9BF8E453CD353C74A2861E2E20230800000001000000D8230000BC856A01C42BA44075D88F5E70549ED2EEC749348587C4305BB4B7B506D58BE5D48EB8AFFA6A67ED30E393BEAA1D4D03D3A5F7C327C24024E6BA1CB380B5BDD763838383FEC5DBA5FC26316DF03A70C873BF303A02AB033026C8AB88625DF1C8518D15B8387A0EAFFA94E00128CCCEE028CA3BB7BBF80E0ACFB725F1AD0F7D6A283FECE39F4D7695A912DC32D4F5B483BD426D60F31EAAAAEF69B513B9ABBC2C30E69E39F8938D8F43E6B29FE991ABD59A162AF1C927252BD7
Note: The AUTH message is protected by the cryptographic algorithms and the keys from the SA_INIT message.
Generally, 'malformed message' error describes that there is a mismatch, possible reasons that the remote side might reject the AUTH message as responder are as follows and the remote side should be checked:
ike 0:VPN:968190: sent IKE msg (SA_INIT): 10.10.10.11:500->192.168.10.11:500, len=240, vrf=0, id=fa9f847249edb233/0000000000000000 ike 0: comes 192.168.10.11:500->10.10.10.11:500,ifindex=7,vrf=0.... ike 0: IKEv2 exchange=SA_INIT_RESPONSE id=fa9f847249edb233/0000000000000000 len=36 ike 0: in FA9F847249EDB2330000000000000000292022200000000000000024000000080000000E ike 0:VPN:968190: initiator received SA_INIT response ike 0:VPN:968190: processing notify type NO_PROPOSAL_CHOSEN ike 0:VPN:968190: malformed message ike shrank heap by 159744 bytes ike 0:VPN:968190: negotiation timeout, deleting ike 0:VPN: connection expiring due to phase1 down ike 0:VPN: deleting ike 0:VPN: deleted
auto: Select ID type automatically. fqdn: Fully Qualified Domain Name. user-fqdn: User Fully Qualified Domain Name. keyid: Key-ID string. address: Local IP address. asn1dn: ASN.1 distinguished name.
Related articles: Technical Tip: IPsec VPN error 'ike Negotiate SA Error: ike ike [1470]' |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.