| Description | This article describes how to resolve an error encountered with an IPsec tunnel between FortiGate to a Third Party device: 'INVALID-HASH-INFORMATION'. |
| Scope | FortiGate. |
| Solution |
We may encounter the above error when PSK is mismatched or when the hash or message authentication code sent by the peer doesn’t match what the receiving end expects.
2024-08-08 10:31:25.814555 ike 0:TPI:364847: notify msg received: INVALID-HASH-INFORMATION 2024-08-08 10:31:41.078087 ike 0:TPI:364847: notify msg received: R-U-THERE By default, FortiGate acts as the initiator.
Refer to this article to make FortiGate act as a responder. For example:
config vpn ipsec phase1-interface edit <tunnel> set passive-mode enable end
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.