Hello together,
I have a little issue with the phase 1 connect state from my fortigate to a remote fritz.box
The configuration on a fritz.box is very limited but it is possible to use a ipsec vpn.
My configuration is:
Authentication: PSK IKE V 1
Mode: Main
Phase 1:
Encryption AES 256 + SHA 1
DH Group : 2
Key Lifetime 8600
Local ID: -
XAUTH: Disabled
At the fritz.box my only options are:
Remote IP,
PSK,
Key-ID
Now I don't know exactly what they mean with key-id.
Where can I create a id in my fortigate to establish a connection ?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I don't know what Fritz box's behavior, but try leaving key-id blank if it accepts. Or set its public IP(NAT outside IP).
On the fitz box key-id is the vpn_user name. So are you trying to use the fortigate as a dialup server to the fitz box? Do you have a dialup vpn setup on the fortigate?
You will need to set up the fortigate for dialup with a local-user account ( use a local user 1st ) and then populate the fitz with the pre-shared key, username and gateway. You might need to mess with the fortigate ciphers to ensure they match the fortigate ph1/ph2.
Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.