FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
fwilliams
Staff & Editor
Staff & Editor
Article Id 254316
Description This article describes troubleshooting steps for the log message 'peer SA proposal not match local policy' on a FortiGate with VPN set up to Microsoft Azure.
Scope FortiGate, FortiOS.
Solution

If the log message 'peer SA proposal not match local policy' is received on a FortiGate with an IPsec VPN connection to Microsoft Azure:

 

  1. Check the phase2 configuration and ensure PFS is unchecked (see the below screenshot) or disable it on FortiGate.
  2. Ensure the key lifetime under phase2 on FortiGate is 27000, especially if there is no access to the Azure side. This is the default value on Azure.
  3. Verify the Encryption/Authentication settings configured for the Phase-2 proposals on both ends.


azurevpn.JPG