Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Karim_namat
New Contributor II

Fortigate VM IPSEC ISSUE

Hello All,

 

Hope you are all doing well, I'm facing an issue today while working on IPSEC on Fortigate VM,

 

 

When I try to create a IPSec VPN tunnel using the wizard this error show up " 61: Input not as expected." as a workaround I create it mannuly to avoid this error but on the Phase2 of VPN Tunnel the fortigate keep loading with out saving the configuration ( screen attached )

 

+The OS info : v7.6.0 build3401

+ Config : 2CPU, 2GB RAM

 

Do you have any recommandation on that ?

 

Regards,

Karim

ERROR.png

GUI.png

7 REPLIES 7
jo_rang
Staff
Staff

Hi,

 

Try to create the VPN via CLI:

 

Phase 1:

 

config vpn ipsec phase1-interface

 

edit "IPSEC"
set interface "wan1"
set peertype any
set net-device disable
set proposal aes128-sha256 aes256-sha256 aes128-sha1 aes256-sha1
set remote-gw 10.9.10.27
set psksecret **********
next
end

 

 

Phase2

config vpn ipsec phase2-interface

edit "IPSEC"
set phase1name "10.9.10.27"
set proposal aes128-sha1 aes256-sha1 aes128-sha256 aes256-sha256 aes128gcm aes256gcm chacha20poly1305
set src-addr-type name
set dst-addr-type name
set src-name "IPSEC_local"
set dst-name "IPSEC_remote"
next
end

Joan
Karim_namat
New Contributor II

Hi @jo_rang 

If you setup it via CLI as a custom via GUI it will work but no logs will be shown on implicit deny for troubleshoot purpose unfortunately.

image.png

sjoshi
Staff
Staff

Hi Karim_namat.

 

Please try to collect FGT GUI output while creating the IPSEC.

 

Related article:

Troubleshooting Tip: Collect GUI slowness and errors debugs via FortiGate Support Tool

Let us know if this helps.
Salon Raj Joshi
Karim_namat
New Contributor II

Hello @sjoshi

 

I believe this is related to the current iOS version, even the wizard has a new view, i will test with old version and keep you updated

 

 

sjoshi

sure

Let us know if this helps.
Salon Raj Joshi
johnlloyd_13
Contributor II

hi,

can you use/provision FG VM 7.4 instead to see whether it's OS/bug related?

Karim_namat

Hi @johnlloyd_13 

 

This must be tested since i'm using free trial i'm only allowed to use one VM peer account, i will test that as well

 

Thank you 

 

Karim

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors