Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
olympian
New Contributor

Invalid SPI when communicating with Openswan

Hi all, I would like to know if Fortiwifi 60C is OK to use with a Openswan Linux server by IPSec. I tried to use the Openswan to collect the Fortiwifi, the tunnel is up and everything seems OK. However when I tried to ping on either side, I got " Invalid SPI" error in the Foriwifi VPN log. However, if I want to connect the Linux from the Fortigate (put the link up on Fortigate, or I should say auto=start from the Fortigate), IPSec SA Phase I is established but not Phase II. No Phase II action is logged/seen in both Fortigate and Linux log. Is there anything I' m missing...? Thanks! Regards, Jason
11 REPLIES 11
olympian
New Contributor

Reply to Message All Forums >>Other FortiGate and FortiOS Topics >>VPN >>
In Quick Mode: All source and destination address = 0.0.0.0/0 B. Regards, Jason
emnoc
Esteemed Contributor III

I' ve always installed the actual subnet in the QM fields that matches what your openswan configuration ( left/right subnet ) This is probably why you have SPI invalid imho.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors