Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ForgetItNet
Contributor

IPsec failure on Phase1 but VPN tunnel listed as N/A ?

I've been setting up SSO with SAML for our IOS devices and I've set it up on a completely different port and WAN IP than the IPsec for our Windows machines (which are working fine). I've got the SSO working to the point that the SSO asks to login and and then passes back to the FortiClient and this then starts connecting but then after a while errors saying "the VPN session failed to connect in a timely manner" so I've checked the FortiAnalyzer which shows it's an issue with "Peer SA proposal does not match local policy" so I've confirmed all the settings are correct on both sides and they are however the problem is that when I've setup IPsec on these before and there's a mismatch the FortiAnalyzer still shows me which VPN tunnel the endpoint is trying to connect to so I'm ok troubleshooting the VPN issue itself but as I've checked the settings are correct then why does it show as N/A and not the IPsec name I've given it for the IOS devices (in case it's related to the cause) ?

Hope that makes sense.

Thanks

 

1 REPLY 1
ForgetItNet
Contributor

Just as an additional note (which I've just realised) is that even though the iPad I'm testing on goes through the SSO and then passes back to the FortiClient to start connecting it fails if I use the "Test User" option on Azure but I'm not sure if that sometimes doesn't work even if the FortiGate side is working and also I've tried it on an iPhone and the SSO shows "You have successfully logged in" but then only gives me the option to cancel and doesn't then even start the VPN connection procedure ? I'm not a fan of apple devices when trying to connect into 3rd party systems at the best of times but I get the impression it could be a wide range of different settings needed on each apple product :)

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors