| Description | This article describes a common issue encountered during the deployment of a new IKEv2 Remote Access VPN solution, which uses certificate-based authentication for clients. The tunnel fails to establish with the error message: 'peer id does not match cert'. This article provides a step-by-step guide to resolve the issue. |
| Scope | FortiGate 7.4.5+ |
| Solution |
To resolve the IKEv2 Remote Access VPN certificate validation issue, follow these steps:
For more information, refer to the FortiGate documentation. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.