Description | This article describes how to troubleshoot the message 'no proposal chosen' when it appears in IKE debug logs. |
Scope | FortiGate v6.4 and v7.2. |
Solution |
When logs collected with 'ike -1' contain 'no proposal chosen' for example, it can be due to any of below:
Debug commands:
diagnose debug application ike -1 diagnose debug enable
Caution: Note that the error message 'no proposal chosen' is NOT the same as 'no SA proposal chosen'. The latter ('no SA proposal chosen') is usually due to a mismatch in the phase 1 encrypt/auth algorithm.
Possible causes of 'no proposal chosen':
config vpn ipsec phase1-interface edit "VPN_Tunnel_name" set localid-type address set localid <IP_address of outgoing interface> end
config vpn ipsec phase2-interface edit "VPN_Tunnel_name" set pfs disable end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.