Description |
This article describes how to resolve an IPsec VPN error when FortiGate does not support a DH group 24, while Azure uses DH value 24. |
Scope | FortiOS all versions. |
Solution |
Run the IPsec VPN debug:
diagnose debug application ike -1 diagnose debug console timestamp enable diagnose debug enable ike 0:Azure_VPN:47553:Azure_VPN:653581: incoming child SA proposal:
To resolve it, configure a different DH group available in FortiGate than 24.
Note: For 'ike Negotiate SA Error: ike ike [11089]', the solution is the same as above.
Related documents: Technical Tip: How to check if Diffie-Hellman(DH) group is the same on both peer units |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.