FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
janonuevo
Staff
Staff
Article Id 342645
Description This article describes how to deal with the IKE negotiation error between FortiGate and Sonicwall.
Scope FortiOS v7.
Solution

CLI commands:


diagnose debug reset
diagnose vpn ike log filter clear
diagnose vpn ike log filter name "IPsec_Tunnel_Name"
diagnose debug application ike -1
diagnose debug enable

 

  1. If the IKE debug message contains the error 'probable pre-shared secret mismatch'.

 

Solution:
Check if the 'Peer ID' on FortiGate matches the 'Local IKE ID' on Sonicwall.

 

On FortiGate:

 

Fortigate1.JPG

 

On Sonicwall:


Sonicwall1.JPG

 

  1. If the IKE debug message contains a 'malformed responder cookie'.

     

     

Solution: (If FortiGate is behind the NAT device).
Check if the 'Peer IKE ID' configured on Sonicwall is the IPv4 interface IP of FortiGate connected to the uplink device.

 

On FortiGate:

                                                      
Fortigate2.JPG
                           
On Sonicwall:
                               

Sonicwall2.JPG