Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AZFortinetMember335
New Contributor II

Forticlient IPSec Dialup Timing out

So we trying to setup a new Dialup IPSec tunnel but we keep getting a connection time out message. We rebuild the tunnel and policies multiple times thinking we missed a step but from the videos we found online this should be the simplest thing to do. I can see the traffic make it to the firewall and I see in the local traffic logs that the traffic is denied (even though we setup local-in-polices) to allow the IKE traffic. 

 

So we are stumped and we are hoping that we are missing something simple that a more experienced person setting these things up might clue us in on. Our firewalls are running 7.4.8 and we are running Forticlient 7.4.3 (We've also tried 7.0.9 and 7.2.9 since some posts we stating older versions worked vs the latest version).

 

I feel something is blocking the traffic on the Firewall I'm just not sure what it could be. Thanks for all and any help.

 

Phil

1 Solution
AZFortinetMember335
New Contributor II

Ok, I figured out what was going on. This is an obvious setting looking back, but for someone setting up for the first time and coming from IKEv1 this could hang you up. If you are just testing proper tunnel setup. Make sure on the Forticlient side of things that you select 'Disable' for "Authentication (EAP)". This was causing the mismatch because we have not setup EAP yet. So an easy gotcha if you are starting from scratch. If this was already setup than you wouldn't have run into the issue I ran into. Thanks for the help. 

View solution in original post

12 REPLIES 12
AZFortinetMember335
New Contributor II

@AEK 

I'll try and get to that next week. Since IKEv1 is up we are working on getting the routing setup. Running into issues with that but trying to work through it. Once we get that aspect solved I can move back to the IKEv2 issue.

AZFortinetMember335
New Contributor II

So it looks like it is trying to negotiate Phase1 Key Exchange but is failing. This is what I see in the logs when the client tries to connect (invalid IKE request SPI). I see 2 different Auth IDs trying to negotiate the exchange but fails. I verified that both setting on the firewall and Forticlient match. Any ideas what to check for?

AZFortinetMember335
New Contributor II

Ok, I figured out what was going on. This is an obvious setting looking back, but for someone setting up for the first time and coming from IKEv1 this could hang you up. If you are just testing proper tunnel setup. Make sure on the Forticlient side of things that you select 'Disable' for "Authentication (EAP)". This was causing the mismatch because we have not setup EAP yet. So an easy gotcha if you are starting from scratch. If this was already setup than you wouldn't have run into the issue I ran into. Thanks for the help. 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors