Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Music_IT
New Contributor

IPSece VPN not working since firmware v7.6.5 build3651 (Mature).

Hi all,
 
I have a FG80 with Automatic updates enabled.
 
Last Saturday it upgraded from version v7.6.2 build3462 to version v7.6.5 build3651 (Mature).
Almost everything works fine but our vpn clients (using IPSec VPN) can no longer connect.
Normally they connect and will get the question to provide the MFA token but that no longer comes.
After a few minutes they will get the error "Connection was terminated unexpectedly.".
 
In de Logs I see:
IPsec phase 1 error with:
Actionnegotiate
Statusnegotiate_error
Reasonpeer SA proposal not match local policy a reason "peer SA proposal not match local policy"
and
Progress IPsec phase 1 with:
Actionnegotiate
Statusfailure
ResultERROR
 
 
Clients are macOS devices running FortiClient VPN 7.4.3.1761.
 
I have already tested it with MFA disabled and that makes no difference.
And yes I have also rebooted the Fortigate.
 
Anyone else experiencing this problem and somebody found fix for it?
 
Rgds
Rob

 

12 REPLIES 12
Music_IT

Hi @HarryTran changing the DH5 to DH14 on both Phase 1 and Phase 2 in both the Fortigate as the Client will give me a wrong user windows and I can try any user they will all fail. Changing it into DH20 will give a an error that the connection is not supported.

I will give it a rest and look at it on another moment.

Thanks for the help and have a great night.
Rob

HarryTran

Hi @Music_IT 

Thanks for your update. 

On next test, kindly use the same debug commands on the FW, and also take screenshot of error shown on client side, then share with us. 
Thanks,

Harry

HarryTran
Staff
Staff

Hi @Music_IT 

Thanks for your update. 

On next test, kindly use the same debug commands on the FW, and also take screenshot of error shown on client side, then share with us. 
Thanks,

Harry

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors