Description | This article describes the problem and solution faced by users when setting up an IPsec tunnel between FortiGate units using IKEv2. |
Scope | FortiGate. |
Solution |
Problem Summary: An IPsec tunnel is established between two FortiGate units. While the tunnel is active with IKEv1, issues arise when transitioning to IKEv2. Specifically, the tunnel is only operational on one FortiGate, with the other unit showing the tunnel as down.
Troubleshooting Steps Undertaken:
2025-02-15 18:44:51.376182 ike 1:BOT_NEW_2021:33390541: initiator received AUTH msg
The Phase1 configuration had both the 'set authmethod-remote psk' and 'set psksecret-remote psk' settings enabled simultaneously.
unset psksecret-remote
Following this adjustment, the tunnel was successfully activated, displaying both incoming and outgoing traffic.
When configuring an IPsec tunnel with IKEv2 between FortiGate units, ensure the Phase1 settings do not simultaneously use both the 'set authmethod-remote psk' and 'set psksecret-remote psk' settings. Removing the redundant setting, specifically 'set psksecret-remote', will likely resolve the issue.
If the tunnel remains down or any other complications are encountered, consider reaching out to FortiGate support for more comprehensive troubleshooting.
In case of a FortiGate handling a high amount - hundreds or more - of IPsec tunnels in IKEv2 mode, an improvement can be made to stabilize the tunnels' performance especially during re-key stage or Security Association SA renegotiation by limiting the number of tunnels establishing SA simultaneously.
Starting from v7.0.0, FortiOS has included the feature to limit the number of simultaneous SA establishment for IPsec tunnels in IKEv2:
Note:
Technical Tip: Asymmetric pre-shared key with IKEv2 for more information on asymmetric authentication. Technical Tip: IKEv2 dialup IPsec tunnel with RADIUS server authentication and FortiClient |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.