Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aagrafi
Contributor II

Receiving authentication error in IKE v.2

Hello,

 

I have configured an IPsec tunnel with IKE v.2 and while troubleshooting the IKE, I'm receiving an unexpected authentication error:

 

ike 0:Trafix_Primary:250162: sent IKE msg (AUTH): x.x.x.x:500->y.y.y.y:500, len=240, id=ad648cb05124d8e0/5f1eee772599fd55:00000001 ike 0: comes y.y.y.y:500->x.x.x.x:500,ifindex=5.... ike 0: IKEv2 exchange=AUTH_RESPONSE id=ad648cb05124d8e0/5f1eee772599fd55:00000001 len=80 ike 0:Trafix_Primary:250162: initiator received AUTH msg ike 0:Trafix_Primary:250162: received notify type AUTHENTICATION_FAILED

 

The problem is that I haven't configured any AUTH in the phase 1 interface:

 

edit "Ph1"         set interface "wan1"         set ike-version 2         set peertype any         set net-device disable         set proposal aes256-sha256         set dhgrp 2         set remote-gw y.y.y.y         set psksecret ....     next

 

Does anybody know where is this failing authentication coming from and how can I resolve the issue? I'm running 6.2.

 

Thanks

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

You're using PSK for AUTH. Likely the PSK is not matching on the other end and it's replying a NOTIFY message with "AUTHENTICATION_FAILED".

aagrafi

This was the problem indeed. I was confused, because I was used in IKE v. 1 debugging, where the PSK mismatch  looks different.

 

Thanks!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors