Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MH1
New Contributor

IPSEC VPN Error

I' m getting the following every few seconds. 2008-11-06 09:24:21 error negotiate failure Responder: parsed XXX.XXX.XXX.XXX quick mode message #1 (ERROR) 2008-11-06 09:24:17 error negotiate failure Responder: parsed XXX.XXX.XXX.XXX quick mode message #1 (ERROR) 2008-11-06 09:24:00 error negotiate failure Responder: parsed XXX.XXX.XXX.XXX quick mode message #1 (ERROR) Eventually the tunnel drops and my users are disconnected. Phase 1 edit " XXXXXX" set interface " wan1" set nattraversal enable set dhgrp 1 set proposal 3des-md5 set remote-gw XXX.XXX.XXX.XXX set psksecret ENC XXXXXXXXXXXXXXXXXXXX next Phase 2 edit " XXXXXXX" set keepalive enable set phase1name " XXXXXXX" set proposal 3des-md5 set dst-subnet 172.16.50.0 255.255.255.0 set keylifeseconds 28800 set src-subnet 192.168.12.0 255.255.255.0 next Policy edit 20 set srcintf " internal1" set dstintf " wan1" set srcaddr " LocalLan" set dstaddr " SonicalWall" set action ipsec set schedule " always" set service " ANY" set logtraffic enable set inbound enable set outbound enable set vpntunnel " XXXXXXX" next Thank you
3 REPLIES 3
abelio
SuperUser
SuperUser

Hi, You' re using DH=1 for phase1 and DH=5 for phase2 Does your sonic wall' s matches those settings?

regards




/ Abel

regards / Abel
MH1
New Contributor

Thank you. I believe the DH was the issue. The sonicwall had 1 and 2 for phase 1 select. I' m also noticing this error that occurs periodically. IPsec DPD detected a failure on the tunnel to XXX.XXX.XXX.XXX:500 Any help would be appreciated.
rwpatterson
Valued Contributor III

Uncheck the dead peer detection (DPD) checkbox on the FGT, then those ' errors' will disappear. They' re actually notifications.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors