Description | This article describes that when integrating an Aruba Gateway with FortiSASE On Ramp, the IPsec IKE negotiation failed at the authentication stage. Logs indicated a pre-shared key (PSK) mismatch, preventing the tunnel from coming up. |
Scope | FortiSASE, FortiGate. |
Solution |
The following log messages were observed on the FortiSASE side during tunnel negotiation:
2025-08-25 10:35:04.398939 ike V=root:0:SDWAN OnRamp 01:102875: responder received AUTH msg
Although the pre-shared key was correct on both sides, an authentication error occurred, and the Aruba device was sending a certificate request even though the authentication method was configured as pre-shared key. In this case, the Aruba team modified specific transform fields to be compatible. After applying the changes, the IKE SA successfully established, and the tunnel came up.
Troubleshooting Checks:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.