Created on
03-12-2024
10:55 PM
Edited on
02-25-2025
06:55 AM
By
Jean-Philippe_P
Description |
This article describes how to process the error 'received notify type AUTHENTICATION_FAILED' obtained when the IPsec tunnel is down. |
Scope | FortiGate. |
Solution |
It is necessary to configure the following settings when the FortiGate is deployed in the Cloud. If it is the first, run IKE debugs and see the error:
Note: In v7.4.0, the 'diagnose vpn ike log-filter dst-addr4' command has been changed to 'diagnose vpn ike log-filter rem-addr4', and starting from FortiOS v7.4.1, the 'diagnose vpn ike log-filter rem-addr4' command has been changed to 'diagnose vpn ike log filter rem-addr4'.
If the following error is visible, it will appear as follows:
2024-03-12 18:07:06.761429 ike 0:Fortigate:370445: sent IKE msg (AUTH): 10.17.4.132:4500->103.9.225.1:4500, len=240, vrf=0, id=d877b92d9f8675a0/5929808be8170f37:0000
Make sure the pre-shared key is matching on both sides. In the IKE version 2 error: received notify type AUTHENTICATION_FAILED can be because of a pre-shared key mismatch between 2 sites. In Cloud platforms, other vendors/remote peers sometimes expect the local ID to be the FortiGate interface Public IP. It is necessary to configure the local ID and local ID type in the phase1-interface.
config vpn ipsec phase1-interface
For certain Meraki or Cisco firewalls, the IPsec VPN may not establish successfully until the 'localid' type is set to 'address'.
config vpn ipsec phase1-interface
If the remote side is another vendor and receiving the same error and FortiGate is behind the NAT device, then configuring the remote-id on Sophos is shown below. The remote ID should be the private IP address of the FortiGate WAN interface.
In case the issue still persists, other localid-types can be configured in FortiGate should the remote peer be expecting a different local ID type from FortiGate. Below are all possible localid-types that can be configured in FortiGate:
Related articles: Technical Tip: IPsec tunnel is not coming up due to error massage AUTHENTICATION_FAILED |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.