Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Chandrasekhar1
New Contributor

IKE_AUTH step is failing when Option DHCP is selected

Hi All,

I am new to this forum, I am trying to setup VPN connection between Nokia 7750 SR router to FortiClient VPN,
below are the config settings.

 

Please note:- This issue happen only Option DHCP is selected, the VPN tunnel comes up correctly when manual IP is selected.

 

Forti VPN Client:-

Authentication Method:- Preshared Key

EAP is disabled

IKE version - 2

Options :- DHCP

PHASE-1

Encryption:-  DES Authentication :- DES

Encryption:-  DES Authentication :- DES

DH Group:- 1

key Life:- 86400

No Local ID

No DPD

No NAT

No Enable Local LAN

 

Phase2 :-

 

Encryption:-  DES Authentication :- DES

Encryption:-  DES Authentication :- DES

Key Life:- 43200

No Relay Detection

No PFS

 

7750 Router is config as IKEv2 with all the config matching to FortiClient VPN. For DHCP option router is dumping below messages.

 

failed because ipsec-gw has local-address-assignment configuration but IKE_AUTH did not contain a config payload."

 

Please find the attached screen shot of all the four packets attached,

It will be really help if you some one can find the root cause.Packet 1.1.pngPacket 1.2.pngPacket 1.3.pngPacket 1.4.pngpacket 2.1.pngpacket 2.2.pngPacket 3.pngpacket 4.png

 

 

 

 

 

 

1 REPLY 1
supajgo1
New Contributor

Post the dhcpd logs, they probably say why it fails to start. Post the full "systemctl status <program>" or figure out where the program is sending logs to and post that https://tutuapp.uno/ .

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors