Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

IPSec Tunnel Issues - weird

I am experiencing a weird issue on a FortiGate 60, MR7. So, the company needs to establish IPSec tunnels with one of major clients. The client has a Checkpoint 41 firewall. They had it set up so we need a different tunnel for each subnet we need to get in (with the same gateway). The first 2 tunnels were established without issues. Now, the 3rd one, cloned after the ones that worked, although is being established without any issues, doesn' t passes any kind of traffic. Tech Details: Phase1: [ul]
  • Mode - Main (the client doesn' t support Aggressive)
  • Authentication: Preshared key
  • Encryption: 3DES
  • Authentication: MD5
  • Keylife: 1800
  • XAuth: disable [/ul] Phase2: [ul]
  • Encryption: 3DES
  • Authentication:MD5
  • Enable replay detection (but NO perfect forward secrecy - PFS) [/ul] The logs show everything fine but once this 3rd tunnel is established, nothing goes through. tcpdump from my end shows that no reply is received. The Checkpoint shows:<br> encryption failure: no response from peer. scheme: IKE Any ideas to get this thing working would be appreciated.
  • 4 REPLIES 4
    UkWizard
    New Contributor

    Make sure they (and you) have the explicit lan subnets specified in the rules. they may be overlapping the subnets at there end, which could cause this. Obviously check that the settings at either end are exact as well.
    UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
    UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
    Not applicable

    Thanks UkWiz for the quick reply. On our end is the same private subnet (192.168.x.x), connecting to different subnets at their end. The difference is that while for the first 2 tunnels (the ones that work) they allowed us into the whole subnet, for the last tunnel they are allowing us only to a specific machine. Could this be an issue? Unfortunately I cannot check the other and I have to trust their security guy.
    UkWizard
    New Contributor

    find out exactly what he is putting in for the encryption domain at his end. Then put the exact subnet & Mask at your end, maybe a mismatch is causing the problem.
    UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
    UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
    Adrian_Lewis
    Contributor

    This is a known problem. The Fortigates use the wrong quickmode ID when setting up a tunnel to a single host. Instead of sending the IPV4_ADDR quickmode type, they send IPV4_SUBNET but with a mask of /32 to mean the host. While this works with some vendors, Checkpoint VPN implementations reject this as an invalid Quickmode ID. There is an interim build which you can get hold of from Fortinet or else you should wait for MR10.
    Labels
    Top Kudoed Authors