Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

IPsec: invalid id...

I am configuring a tunnel with some checkpoint firewall. I have created a phase1 (main mode) SA and no problems here. I have also established a phase 2 from forti-->checkpoint. (ping wokrs) however when attempting phase 2 from checkpoint--> forti (pinging to forti' s lan) I get the infamous: " Peer' s id payloads do not match local policy." the forti says " Negotiate SA Error: Peer' s id payloads do not match local policy." here' s what I' ve configured on the forti. I' d appreciate it if you could help me check my settings and decide where the problem is... thanks! on the forti (100a BTW): defined a subnet for my local subnet (subnet_a) defined a subnet for the remote subnet (subnet_b) created a main mode VPN with relevant parameters (no problem here) created a quick mode VPN with relevant paramters. in selectros, I' ve configured subnet_a' s address as source and subnet_b' s address as destination. however subnet B originally has a 30bit SubnetMask but connections were not being accepted until I have configured it under selectors as a 29bit subnet. I do not understand this. also, If I configured it as a 0.0.0.0/0 selector the connection was also accepted with no problems. this is the connections from fortie-->checkpoint. I have created a rule on my outbound (internal: subnet_a to wan1: subnet_b) and set the rule to encrypt etc. (rule allows outgoing and incomoing) this works ok. I have also created an allow rule (not encrypt) for the wan1 to internal traffic: wan1: subnet_b to internal: subnet_a, allow. additionally, I have tried using interface mode (virtual interface), and added a route to the destination (subnet_b) for that to work. the results were basically the same. any help appreciated. thanks! -Shay in interface mode, I have configured 2 " allow" policy for local to remote and remote to local traffic. again, local to remote works but not the other way around. no matter WHAT I do, when pinging from subnet_b to subnet_a, forti says: " Peer' s id payloads do not match local policy." also the checkpoint says : notification from peer - " invalid id information" I thank you very much for your time and attention, plz helllllp... -Shay
5 REPLIES 5
player
New Contributor

hey Shay, if you are using forti os-v.3 please verify that the quick mode in phase2 is also configured - you need to apply the subnets (from local to remote) in the quick mode fields.
player. rock the boat , dont sink the ship
player. rock the boat , dont sink the ship
Not applicable

Hi Player, thanks for your reply. this is RTFM - I' ve done this. in fact I have tried several variations including all 0' s, correct addresses for both Local and Remote and other variations. BTW I have seen this issue occour with one other CheckPoint firewall (VPN to some other device, I think it was a cisco). nonetheless, no matter what I do: the errors appear, and I can' t ping from B to A. Ping from A to B works fine ! anyway, thanks for the help! -Shay
Not applicable

I had this problem before with a Checkpoint, I think they need to enable " key exchange for subnets" to get it to understand the fortinet .
Not applicable

hello, I have the same problem here. call is already open. what I found out: I have one FGT configured in V2.8, then upgraded to 3.0 and the VPN works. in the quick-mode-configuration, no networks are shown. there are the names of the network-groups shown!!! no IP-adresses at all. then I tried to enter the names of the groups in a new config in V3.0. but this does not work. regards andy
player
New Contributor

are you using the (PFS) option ?
player. rock the boat , dont sink the ship
player. rock the boat , dont sink the ship
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors