Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

NO_PROPOSAL_CHOSEN

Hi, I' m trying to connect a forticlient v. 2.0.1.148 on a fortigate 50a 2.8 build489 when I do a test : Negotiate SA Error protocol_id=1, notify_msg=14 (NO_PROPOSAL_CHOSEN), ispi_size=0 any ideas?
3 REPLIES 3
Not applicable

check your phase1 settings (proposed algorithms should be equal to the ones on the client) (you propably already checked this). What I experienced was that I was able to connect, but another fellow couldn' t, even if he used " my" VIP. If he imported my policy, first then he was able to connect through vpn. All the settings were identical... forticlient is just pure magic.
Not applicable

Thanks, phase 1 is ok now, I had to add proposal 2 in each phase. I have tried on two diff. laptops with two diff. vpn clients @home and @work, but it still doesn' t work. Maybe a problem with my fortigate config.... This is the log error I get for my vpn client on my laptop: SENDING>>>> ISAKMP OAK QM *(HASH, SA, NON, KE, ID 2x) RECEIVED<<< ISAKMP OAK INFO *(HASH, NOTIFY:INVALID_ID_INFO) Is it a ip address problème? A pre-shared key problem? Thank you in advance :)
Not applicable

are you using a licenced version of forticlient? phase 1 and phase 2 must be similar at the client and the fortigate. The evaluation version of the client doesn' t support 3DES or AES, only DES... the hashing must me the same, if the fgt is configured with sha-1, so should the client.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors