Created on
02-03-2023
01:21 AM
Edited on
11-29-2024
01:16 AM
By
Jean-Philippe_P
Description | This article describes how to troubleshoot IPSec error: 22: Invalid argument. |
Scope | FortiGate. |
Solution |
FG-A: [IPSec_local]. IPSec_local_subnet_1: 10.251.0.0/20. IPSec_local_subnet_2: 10.251.0.0/24. [IPSec_remote]. IPSec_remote_subnet_1: 10.120.0.0/20.
FG-B: [IPSec_local]. IPSec_local_subnet_1: 10.120.0.0/20. [IPSec_remote]. IPSec_remote_subnet_1: 10.251.0.0/20. IPSec_remote_subnet_2: 10.251.0.0/24.
Removing 10.251.0.0/24 from the address group on both FortiGate would prevent the IPSec tunnel issue regardless if FG-A or FG-B becomes the initiator. |