Description | This article describes the troubleshooting for the log message: 'peer SA proposal not match local policy' on FortiGate with VPN to Microsoft Azure. |
Scope | FortiGate, FortiOS. |
Solution |
If receiving the Log message 'peer SA proposal not match local policy' on FortiGate which has IPsec VPN to Microsoft Azure, check the phase2 configuration and ensure PFS is unchecked (see the below screenshot) or disable it on FortiGate.
Also ensure the key lifetime under phase2 on FortiGate is 27000, especially if not having access to the Azure side, this is the default value on Azure. |