Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fortiben1
New Contributor III

Negotiate and Success

Hi People!,

 

I just want to ask regarding the IPsec VPN logs. We found a malicious remote IP address in our logs. I want to ask what the status = Success and 1 is negotiate_error, and the message = progress IPsec phase 2 and IPsec phase 1 SA mean. Does this indicate that the malicious IP has successfully penetrated? What are the possible troubleshooting steps or solutions to stop this?

 

Thank you! 

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Ben

I guess this is a dial-up IPsec.

 

Does this indicate that the malicious IP has successfully penetrated?

-> I think if he managed to connect successfully then you should see a message like "Tunnel up" and clearly identify the username. Or at lease you may check the traffic logs to see if there was any suspicious traffic.

 

Regarding your last question, I'd use 2FA for better security (password + token or mail OTP).

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors