Description |
This article describes the error encountered for FortiOS to AWS VPN after upgrading to version (7.4.2 and above) where the VPN anti-spoof feature was introduced. |
Scope |
FortiGate v7.4.2 and above |
Solution |
id=65308 trace_id=20320 func=ipsec_spoofed4 line=245 msg="src ip 10.100.1.38 mismatch selector 0 range 169.254.189.57-169.254.189.57" id=65308 trace_id=20320 func=ipsec_input4 line=289 msg="anti-spoof check failed, drop"
! #2: IPSec Configuration Under Phase 2 Selectors --> New Phase 2 Name: vpn-xxxx Local Address: LAN subnet behind Fortigate/0.0.0.0/0 Remote Address: AWS Private Subnet/0.0.0.0/0 |