Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TobiasHan
New Contributor

Fortigate Sophos VPN ISAKMP SA still negotiating

Hello,

 

i have a Fortigate 500D with Firmware v.5.4.2 and i try to build a VPN-Tunnel to a Sophos UTM 9.

 

I have made a VPN-Tunnel to the Remote Address (IKE Gateway) from the Sophos Firewall.

 

When i make a

diag vpn ike log-filter name diag debug app ike -1 diag debug enable

 

i get following output:

IPsec SA connect 35 xx.xxx.xxx.x->xx.xxx.xx.xxx:0 using existing connection config found IPsec SA connect 35 xx.xxx.xxx.x->xx.xxx.xx.xxx:500 negotiating ISAKMP SA still negotiating, queuing quick-mode request

 

 

what does the still negotiating mean? Is this the error?

 

With Best Regards TobiasHan

2 REPLIES 2
TobiasHan
New Contributor

Problem found. Wrong Remote IP Adress.

 

Regards

oheigl
Contributor II

My guess is you need the same output from the Sophos Firewall, because something is wrong on the other side. The FortiGate doesn't seem to have a problem, but most of the time you only see the mismatch on one side of the VPN negotiation. Do you have some log output from the remote side?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors