Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aidangregory
New Contributor

IPsec VPN issue

We currently have an RA IPsec VPN that provides access to the production subnet. I have attempted to create a new RA IPsec VPN that provides access to the management subnet. I created a new VPN with different PSK, IPv4 client range, split tunnel subnet but everything else is configured the same. This was previously working but is no longer working.

 

I can see from the logs that Ike phase 1 is negotiation is not completing successfully, and I can see in the logs "SA proposal chosen, matched gateway XXXX", but I am trying to connect to gateway Y. I have compared all settings of VPN X and Y, and forticlient config of X and Y and everything appears to be correct.

 

I previously managed to get this VPN working as intended, but then had issues when trying to configure it for SAML authentication. All I did today was reverted back to local user but this never worked again. I have completely removed all configuration required and re-created but this is still failing

 

Production VPN peer ID is any, while the MGMT VPN peer ID is our public IP.

 

FortiGate 60-F running version 7.6.0

3 REPLIES 3
aidangregory
New Contributor

Adding to this we have created an identical FW policy that uses the MGMT VPN interface/subnet + a new static route for the client IP subnet range using the VPN tunnel interface as default gateway

ebrlima
Staff
Staff

Please share your ipsec tunnel configuration and the output of:

 

 

diagnose vpn ike log filter name "phase1 name"

diagnose debug application ike -1

diagnose debug enable

Eudes Lima
ede_pfau
SuperUser
SuperUser

Nearly identical dial-up VPNs on the same public WAN IP need to be differentiated by a "peer ID". You didn't mention it, have you implemented it? 2 simple strings will do so that the FGT can decide which VPN a request is aimed at.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors