Created on
06-08-2025
02:24 PM
Edited on
11-23-2025
11:39 PM
By
Jean-Philippe_P
| Description | This article describes how to resolve the 'IKEv2: unexpected payload type 41' error seen in IKE debugs while troubleshooting a Dial-Up IPsec VPN with IKEv2. |
| Scope | FortiGate, FortiClient macOS. |
| Solution |
When troubleshooting Dial Up IPsec VPN with IKEv2, the following error is seen in IKE debugs:
ike V=root:0:IPsec-Home-W:17: responder received EAP msg
Following IKE debugs can be run to troubleshoot the Dial Up IPSEC VPN issues:
diagnose vpn ike log-filter clear diagnose debug application fnbamd -1 <---- Enable to see for any authentication issue.
To stop the debugs:
diagnose debug disable diagnose debug reset
Note:
This issue was reported with FortiClient macOS 14 and 15. To resolve this issue, check the preshared key on both sides (FortiGate and FortiClient) and make sure that they are the same.
ISAKMP payload 41 is 'Notify'. This payload has different sub-types. When the presharded key does not match, macOS FortiClient will send a 'Notify type 24 (AUTHENTICATION_FAILED)'.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.