Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
darrencarr
New Contributor II

IPSEC tunnel error

Guys I keep getting this error on a link between two sites and am not sure what is causing it? It takes the tunnel down. I can go back in and select ' Bring Up' and it comes back no problem. Any idea what could be causing this? 2009-05-18 10:43:52 device_id=FGTxxxxxxxxx log_id=0101023003 type=event subtype=ipsec pri=error vd=root loc_ip=x.x.x.x loc_port=500 rem_ip=x.x.x.x rem_port=500 out_if=" xxxxxx" vpn_tunnel=" unknown" cookies=40a62cfbde18be7f/0000000000000000 action=negotiate status=negotiate_error msg=" Negotiate SA Error: No matching gateway for new phase 1 request." Thanks D
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
7 REPLIES 7
g3rman
New Contributor

try this: diag debug enable diag debug console diag debug app ike 3 <ip address of remote firewall> and post some of the output. That will help diagnose the problem.
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
darrencarr
New Contributor II

Hi g3rman... Thanks for the reply. Please see the below. The initial lines are when the tunnel has gone down. When I issue the ' Bring Up' command please see below this heading... thanks FW003 # 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19525 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 shrank heap by 4096 bytes 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:405a226c len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19526 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:8ba96415 len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19527 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:a0700df9 len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19528 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:1f97e96a len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19529 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:56324071 len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19530 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:2267b9b8 len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1:DR_2_HQ_OPTUS_P2: IPsec SA connect 18 172.x.x.x->172.x.x.x:500, natt_mode=0 0:DR_2_HQ_OPTUS_P1: using existing connection, dpd_fail=0 0:DR_2_HQ_OPTUS_P1: found phase2 DR_2_HQ_OPTUS_P2 0:DR_2_HQ_OPTUS_P1: IPsec SA connect 18 172.x.x.x->172.x.x.x:500 negotiating 0:DR_2_HQ_OPTUS_P1:1729: cookie 40a62cfbde18be7f/6c819c12147b90fd:5037add1 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: initiator selectors 0 0.0.0.0/0.0.0.0:0->0.0.0.0/0.0.0.0:0 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (quick_i1send): 172.x.x.x:500->172.x.x.x:500, len=388 DR_2_HQ_OPTUS_P1: Initiator: sent 172.x.x.x quick mode message #1 (OK) 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... BRING UP (command issued) ============================================================================================================= 0: exchange=Quick id=40a62cfbde18be7f/6c819c12147b90fd:5037add1 len=356 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: responder selectors 0 0.0.0.0/0.0.0.0:0->0.0.0.0/0.0.0.0:0 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (quick_i2send): 172.x.x.x:500->172.x.x.x:500, len=60 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: set sa life soft seconds=1774. 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: set sa life hard seconds=1800. 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: add SA #src=1 #dst=1 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: src 0 4 0.0.0.0/0.0.0.0 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: dst 0 4 0.0.0.0/0.0.0.0 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: installed SA: SPIs=c41c4983/8403fb54 0:DR_2_HQ_OPTUS_P1:1729:DR_2_HQ_OPTUS_P2:201570: sending SNMP tunnel UP trap DR_2_HQ_OPTUS_P1: Initiator: sent 172.x.x.x quick mode message #2 (DONE) shrank heap by 126976 bytes 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19532 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:6875696d len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19533 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:37e6d18b len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK FW003 # diagnose de0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19534 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:93bb3570 len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK bug disable
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
darrencarr
New Contributor II

Sorry guys my dump earlier was poor... please see below... unable to restablish after the SA expires 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19890 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:bc4f0558 len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK 0:DR_2_HQ_OPTUS_P1: IPsec SA 8403fb54/c41c4983 hard expired 18 172.x.x.x->172.x.x.x:500 SAs left 0 of 0 0:DR_2_HQ_OPTUS_P1:1729: send IPsec SA delete, spi 0xc41c4983 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (IPsec SA DELETE-NOTIFY): 172.x.x.x:500->172.x.x.x:500, len=76 0:DR_2_HQ_OPTUS_P1: sending SNMP tunnel DOWN trap for DR_2_HQ_OPTUS_P2 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:97f8a74d len=76 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: recv IPsec SA delete, spi count 1 0:DR_2_HQ_OPTUS_P1: deleting SA with SPI 8403fb54 0:DR_2_HQ_OPTUS_P1: SA with SPI 8403fb54 does not exist 0:DR_2_HQ_OPTUS_P1: send DPD probe, seqno 19891 0:DR_2_HQ_OPTUS_P1:1729: sent IKE msg (R-U-THERE): 172.x.x.x:500->172.x.x.x:500, len=92 0: comes 172.x.x.x:500->172.x.x.x:500,ifindex=18.... 0: exchange=Informational id=40a62cfbde18be7f/6c819c12147b90fd:64293a33 len=92 0: found DR_2_HQ_OPTUS_P1 172.x.x.x 18 -> 172.x.x.x:500 0:DR_2_HQ_OPTUS_P1:1729: notify msg received: R-U-THERE-ACK
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
darrencarr
New Contributor II

Guys I have resolved the problem... I really should look in the kc.forticare before posting... Cheers Darren
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
rwpatterson
Valued Contributor III

What the heck was it?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
darrencarr

At this stage I am only testing the VPN and new WAN link connection and not passing any traffic I think after the timeout expired asI was not sending any traffic the VPN was coming down. I' m kind of new to this and then read a couple of articles and realised I had not enabled the keep alive on phase 2 as it suggested in the document. I have since enabled this and the tunnel is now staying up. Learn something new every day and also learnt to read more before posting and wasting peoples time!
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
Fortigate 1000A v4.0,build194,100121 (MR1 Patch 4) Fortianalyzer 800B v4.0,build0130 (MR1 Patch 3)
rwpatterson
Valued Contributor III

It' s only a waste of time if you didn' t learn from it...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors