Description | This article describes the solution for the error 'mismatched DH group in KE payload' received in IKE debugs. |
Scope | FortiGate. |
Solution |
The following error is noticed in the IKE debugs: 'mismatched DH group in KE payload'. 2025-06-10 12:43:14.462965 ike V=root:0:IPSecVPN:56: mismatched DH group in KE payload, selected 14, received 5 This error occurs when a negotiation failure happens for the DH-Group. In the above error, it can be concluded that FortiGate is receiving negotiation for DH-Group=5, but on FortiGate, DH-Group is set to 14.
More information on how to check regarding DH group can be found in this KB article: Technical Tip: How to check if Diffie-Hellman(DH) group is the same on both peer units
Execute following debug commands to collect IKE logs:
Note: Troubleshooting Tip: Troubleshooting IPsec Site-to-Site Tunnel Connectivity |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.