Hi People!,
I just want to ask regarding the IPsec VPN logs. We found a malicious remote IP address in our logs. I want to ask what the status = Success and 1 is negotiate_error, and the message = progress IPsec phase 2 and IPsec phase 1 SA mean. Does this indicate that the malicious IP has successfully penetrated? What are the possible troubleshooting steps or solutions to stop this?
Thank you!
Hi Ben
I guess this is a dial-up IPsec.
Does this indicate that the malicious IP has successfully penetrated?
-> I think if he managed to connect successfully then you should see a message like "Tunnel up" and clearly identify the username. Or at lease you may check the traffic logs to see if there was any suspicious traffic.
Regarding your last question, I'd use 2FA for better security (password + token or mail OTP).
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.