Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
famany
New Contributor

Fortigate <-> Strongswan VPN problem with VRRP

Hi all,

 i've configured a ipsec tunnel sito-to-site in a Fortigate cluster on Openstack environment.

 

This 2 fortigate are in cluster but only for sync the configuration, because in openstack the HA Cluster don't work.

The nodes sync good the configuration and i've configured a VRRP for the networks.

 

When i try to configure strongswan i insert the public ip of the vrrp in the strongswan configuration, but when i try to connect i see in the swan logs this:

Oct 30 17:47:49 famany-VM charon: 07[IKE] initiating IKE_SA CRIVPN-Test[126] to public_ip_vrrp
Oct 30 17:47:49 famany-VM charon: 07[ENC] generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(HASH_ALG) N(REDIR_SUP) ]
Oct 30 17:47:49 famany-VM charon: 07[NET] sending packet: from 192.168.0.50[500] to public_ip_vrrp[500] (328 bytes)
Oct 30 17:47:51 192.168.0.1 IGMP: V2 igmp router occured! Not matching ours V3.
Oct 30 17:47:53 famany-VM charon: 14[IKE] retransmit 1 of request with message ID 0
Oct 30 17:47:53 famany-VM charon: 14[NET] sending packet: from 192.168.0.50[500] to public_ip_vrrp[500] (328 bytes)
Oct 30 17:48:00 famany-VM charon: 05[IKE] retransmit 2 of request with message ID 0
Oct 30 17:48:00 famany-VM charon: 05[NET] sending packet: from 192.168.0.50[500] to public_ip_vrrp[500] (328 bytes)
Oct 30 17:48:13 famany-VM charon: 12[IKE] retransmit 3 of request with message ID 0
Oct 30 17:48:13 famany-VM charon: 12[NET] sending packet: from 192.168.0.50[500] to public_ip_vrrp[500] (328 bytes)
Oct 30 17:48:17 famany-VM charon: 15[NET] received packet: from public_ip_NODE1[500] to 192.168.0.50[500] (464 bytes)
Oct 30 17:48:17 famany-VM charon: 15[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(FRAG_SUP) ]
Oct 30 17:48:17 famany-VM charon: 15[IKE] no IKE config found for 192.168.0.50...public_ip_NODE2, sending NO_PROPOSAL_CHOSEN

 

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors