Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luca1994
Contributor

VPN IPSec between two fortigate: phase 1 ike msg retransmit

Hello team,

 

this is the scenario:

IPSec peers are both public ip so I left NAT-T disabled and enabled DPD Peer detection on demand for both firewalls.
As authentication I set PSK, IKEv1 Main (id protection) for both firewalls.
For the Phase1 Proposal part I configured AES256-SHA1 and DH 21 and 2 for both firewalls.
After that I configured the relevant policies and static route for both firewalls.

The problem is that phase1 does not go up. Running some debugging I see this in the logs:

ike debug1.pngike debug2.png

I also ran a packet capture and I see traffic on port 500 for both firewalls:

 

sniffer2.pngsniffer1.png

 

 

Thanks in advance for the support

BR

1 Solution
AEK

Hi Luca

I mean your issue may occur if the remote peer IP (FG-B) is conflicting with an IP set on the local FortiGate (FG-A).

Try check on FG-A may be you have a VIP or IP pool that contains the remote peer IP. In that case during negotiation packets are sent to the local FG instead of FG-B.

AEK

View solution in original post

AEK
4 REPLIES 4
AEK
SuperUser
SuperUser

Hi Luca

Check on your local FG if the remote peer IP is set on some interface or as VIP or IP pool.

AEK
AEK
luca1994

Hi @AEK ,

 

the remote peer IP is set on interface, also local peer.

 

BR

AEK

Hi Luca

I mean your issue may occur if the remote peer IP (FG-B) is conflicting with an IP set on the local FortiGate (FG-A).

Try check on FG-A may be you have a VIP or IP pool that contains the remote peer IP. In that case during negotiation packets are sent to the local FG instead of FG-B.

AEK
AEK
hbac
Staff
Staff

Hi @luca1994,

 

Can you run debugs on the other side? 

 

Regards, 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors