Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zeev
New Contributor

IPSec AutoKey(IKE) Phase2 Problem - help

Hi forum, I' ve bought Fotigate 30B on which i' ve configured(only option) VPN/IPSEC/AutoKey(IKE). My configuration is for dial-up server, where the server itself is the fortigate(using group i created earlier). I manage to finish phase 1 of the connection, and as i understand also parts of phase2, but it always gets stuck at the same part: Jul 5 9:30:49: Initiator: sent <FortiWANIP> quick mode message #1 (OK) Now i don' t know what to do with the quick mode. I' ve read alot bout it, and all places direct me to keep it on it' s default(0.0.0.0/0) for dial-up server configuration. I try to connect using a forticlient. Please, if anyone could share more info and help me with this, i' ve been trying to get it to work for 5 days with all sorts of configurations.
11 REPLIES 11
Zeev
New Contributor

Thanks for reply emnoc, But i have MR3, and i read the manual. I' ve installed BY the manual(since i' ve never done AutokeyIKE vpn before). This is why i' m here. It has nothing to do with Phase 1 cfg, it reachs phase 2. i ran it and watched the debug diag, and it gets stuck on the same point: peer has not completed Configuration Method then bunch of talk between client and forti. And then: 0:57: notify msg received: R-U-THERE-ACK: fromforti to client. 0:57:comes client:500 -> forti:500,ifindex=3.... IKEv1 exchange=Quick id=<cant show u this> in long string of randomness.... and then repeats the same procedure over and over again.... and i can see the sequance number rising everytime so i know it' s stuck there... but what is it looking for?
Zeev
New Contributor

Solved it myself.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors