Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zeev
New Contributor

IPSec AutoKey(IKE) Phase2 Problem - help

Hi forum, I' ve bought Fotigate 30B on which i' ve configured(only option) VPN/IPSEC/AutoKey(IKE). My configuration is for dial-up server, where the server itself is the fortigate(using group i created earlier). I manage to finish phase 1 of the connection, and as i understand also parts of phase2, but it always gets stuck at the same part: Jul 5 9:30:49: Initiator: sent <FortiWANIP> quick mode message #1 (OK) Now i don' t know what to do with the quick mode. I' ve read alot bout it, and all places direct me to keep it on it' s default(0.0.0.0/0) for dial-up server configuration. I try to connect using a forticlient. Please, if anyone could share more info and help me with this, i' ve been trying to get it to work for 5 days with all sorts of configurations.
11 REPLIES 11
Zeev
New Contributor

Thanks for reply emnoc, But i have MR3, and i read the manual. I' ve installed BY the manual(since i' ve never done AutokeyIKE vpn before). This is why i' m here. It has nothing to do with Phase 1 cfg, it reachs phase 2. i ran it and watched the debug diag, and it gets stuck on the same point: peer has not completed Configuration Method then bunch of talk between client and forti. And then: 0:57: notify msg received: R-U-THERE-ACK: fromforti to client. 0:57:comes client:500 -> forti:500,ifindex=3.... IKEv1 exchange=Quick id=<cant show u this> in long string of randomness.... and then repeats the same procedure over and over again.... and i can see the sequance number rising everytime so i know it' s stuck there... but what is it looking for?
Zeev
New Contributor

Solved it myself.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors