Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nachoju
New Contributor

Peer SA proposal not match local policy - FORTI 100E - AZURE

Hi all,

I am having some problems with the Vpn to Azure. I receive this message each 5 minutes from the fortigate. VPN seems to be up but some services fails and I have to bring it down and bring it up again to continue working.

 

Can any one help me? I am new with fortigate.

Thank you in advance.

 

 

Messages:

Message meets Alert condition

date=2017-09-05 time=12:22:01 devname=FG100E-**** devid=FG100E4Q17000357 logid="0101037189" type="event" subtype="vpn" level="error" vd="root" logdesc="IPsec phase 2 error" msg="IPsec phase 2 error" action="negotiate" remip=**** locip=**** remport=500 locport=500 outintf="ppp1" cookies="9213e89c8037d2c6/de8a50a6809f7c00" user="N/A" group="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="VPN_Azure" status="negotiate_error" reason="peer SA proposal not match local policy"

 

Message meets Alert condition

date=2017-09-05 time=12:20:01 devname=FG100E-**** devid=FG100E4Q17000357 logid="0101037189" type="event" subtype="vpn" level="error" vd="root" logdesc="IPsec phase 2 error" msg="IPsec phase 2 error" action="negotiate" remip=**** locip=**** remport=500 locport=500 outintf="ppp1" cookies="9213e89c8037d2c6/de8a50a6809f7c00" user="N/A" group="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="VPN_Azure" status="negotiate_error" reason="peer SA proposal not match local policy" 

 

 

6 REPLIES 6
Agent_1994
Contributor

I assume that you verified that the FG phase 2 matches Azure.

Did you try this?

 

diagnose debug enable diagnose debug application ike -1

It's output should help

 

nachoju

thank you for your suggestions. I have reset the router and now i stopped from receiving this messages and now it seems to be ok. 

 

Probably the router was filtering anything on 500/4500 ports. 

 

thank you!!

yannick22

Had same problem. Did run "diagnose vpn ike restart" which fixed it.

 

FortiGate 100E v5.4.12,build8180 (GA)

Boboladele

Worked for me too. Thanks a bunch

tommyhylden

That worked for me

Allan_Lago
New Contributor

Hi,

 

Please review your phase 1 and phase 2 proposal configuration on both sites.

 

They have to match the same encryption and authetication settings on both sides.

 

Regards,

 

 

 

   Allan Lago

   Security Analist

   allan.lago@itsense.com.br

   +55 21 96436-1884

   +55 54 99100-0949

   https://itsense.com.br

Allan Lago Security Analist allan.lago@itsense.com.br +55 21 96436-1884 +55 54 99100-0949 https://itsense.com.br
Labels
Top Kudoed Authors