Description |
This article describes how to process the error 'received notify type AUTHENTICATION_FAILED' obtained when the IPsec tunnel is down. |
Scope | FortiGate. |
Solution |
It is necessary to configure the following settings when the FortiGate is deployed in the Cloud. If it is the first, run IKE debugs and see the error:
diagnose debug reset
Note: If firmware older than v7.4.1 is being used, such as v7.2, v7.0, or v6.X: use the 'diagnose vpn ike log-filter dst-addr4' command instead of 'diagnose vpn ike log filter rem-addr4'. In v7.4.0, use the 'diagnose vpn ike log filter dst-addr4'.
If the following error is visible, it will appear as follows:
2024-03-12 18:07:06.761429 ike 0:Fortigate:370445: sent IKE msg (AUTH): 10.17.4.132:4500->103.9.225.1:4500, len=240, vrf=0, id=d877b92d9f8675a0/5929808be8170f37:0000 02900003408DDB68445805F9546822E9AAED2872950F08084B196277203B901495E095CAC23
Make sure the pre-shared key is matching on both sides. In the IKE version 2 error: received notify type AUTHENTICATION_FAILED can be because of a pre-shared key mismatch between 2 sites.
In Cloud platforms, other vendors/remote peers sometimes expect the local ID to be the FortiGate interface Public IP. It is necessary to configure the local ID and local ID type in the phase1-interface.
config vpn ipsec phase1-interface
For certain Meraki or Cisco firewalls, the IPsec VPN may not establish successfully until the 'localid' type is set to 'address'. On Meraki, there are cases that need to set the remote ID and the FortiGate WAN IP and remove the set local ID on the FortiGate.
config vpn ipsec phase1-interface
If the remote side is another vendor and receiving the same error and FortiGate is behind the NAT device, then configuring the remote-id on Sophos is shown below. The remote ID should be the private IP address of the FortiGate WAN interface.
In case the issue persists, other localid-types can be configured in FortiGate should the remote peer be expecting a different local ID type from FortiGate. Below are all possible localid-types that can be configured in FortiGate:
For example, if the FortiGate is behind a NAT device and has a private IP address on its WAN interface, configure this private IP address as the CPE IKE identifier in Oracle.
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.