Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zorg1983
New Contributor

IPSEC tunnels fail all the time

Hello All,

 

I have an issue with a client who has a FGT 100D with 5.2.3

 

There are 3 IPSEC tunnels , 2 interface mode 1 tunnel mode. all of the tunnel are agains PFSENSE firewalls.

 

I get a lot of errors such as negotiate , phase 1 deleted , phase 2 success. ESP packet error and cetra...

 

Today i spoke with a technical person from the other side and there was some problems with the seconds . it was corrected but the errors keep coming.

 

Any ideas?

 

Joe.

1 REPLY 1
emnoc
Esteemed Contributor III

It would help to know more about "what's" failing  and the configuration. I've used pfsense with vpns to various cisco ( router/asa ) ,juniperSRX  and fortigates with zero issues for over the lasy 5 years. The same can be sad of strongswan.

 

As long as you set the phase1/2 SAs to match, you should not have any noticeable issues. try to stay away from ike-version "auto" in 2.2 pfsense and limit the cipher/dhgrp to the exact match in phase1 initial offering.

 

Same for the phase2 proxy-ids, strike all ciphers that's not supported on a FGT ( blowfish,cast,etc,..) and just define the one that you want.

 

The following link shows some basic t-shooting ideals.

http://socpuppet.blogspot.com/2013/10/site-2-site-routed-vpn-trouble-shooting.html

 

 

ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors