Hello,
I have a problem with establishing a site to site VPN, we have fortigate 60E on our side and cisco ASA on partners side.
You'll find bellow the results of the debug:
2023-04-11 04:56:12.586859 ike 0:VPN-X:10634: out 7C4EE6958EB809940000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500007B8DC496C30E865C1796B8CAF210EB69BB3D59EBE2874CDAF4792857CA7B126D9038879AD02D883D3065C9771AE40D47429296C68E7CEF147BB00EE2B0CDA28C1981DD318990E91121329743D4B5464716E8C288CCDDA5CE6D031E2F29C742EBDBB3FB70DFD9C1EACAF7002F9FB8C52085A83D10076826C0E1047C93EEB9255DB9DC91963B18B921E8602C785E908E2B223A713265CCBBF1A9633CD3B8260EBFF71A7A83AE96079D61C0E18ED4AE531213456D97E785BA948874D024E12A71DB29000014F9300D4BEE615BF91D43479DF27CC3082900001C00004004FA471070E89A907177FAAE1E9AAA8B9320649CD70000001C0000400566197531D175933B8640C0E6AE2033C179E31A60
2023-04-11 04:56:12.587079 ike 0:VPN-X:10634: sent IKE msg (RETRANSMIT_SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=7c4ee6958eb80994/0000000000000000
2023-04-11 04:56:15.576877 ike shrank heap by 122880 bytes
2023-04-11 04:56:24.596856 ike 0:VPN-X:10634: out 7C4EE6958EB809940000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500007B8DC496C30E865C1796B8CAF210EB69BB3D59EBE2874CDAF4792857CA7B126D9038879AD02D883D3065C9771AE40D47429296C68E7CEF147BB00EE2B0CDA28C1981DD318990E91121329743D4B5464716E8C288CCDDA5CE6D031E2F29C742EBDBB3FB70DFD9C1EACAF7002F9FB8C52085A83D10076826C0E1047C93EEB9255DB9DC91963B18B921E8602C785E908E2B223A713265CCBBF1A9633CD3B8260EBFF71A7A83AE96079D61C0E18ED4AE531213456D97E785BA948874D024E12A71DB29000014F9300D4BEE615BF91D43479DF27CC3082900001C00004004FA471070E89A907177FAAE1E9AAA8B9320649CD70000001C0000400566197531D175933B8640C0E6AE2033C179E31A60
2023-04-11 04:56:24.597050 ike 0:VPN-X:10634: sent IKE msg (RETRANSMIT_SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=7c4ee6958eb80994/0000000000000000
2023-04-11 04:56:36.586845 ike 0:VPN-X:10634: negotiation timeout, deleting
2023-04-11 04:56:36.589409 ike 0:VPN-X: connection expiring due to phase1 down
2023-04-11 04:56:36.589449 ike 0:VPN-X: deleting
2023-04-11 04:56:36.589471 ike 0:VPN-X: flushing
2023-04-11 04:56:36.589651 ike 0:VPN-X: flushed
2023-04-11 04:56:36.589714 ike 0:VPN-X: deleted
2023-04-11 04:56:36.589741 ike 0:VPN-X: schedule auto-negotiate
2023-04-11 04:56:37.596860 ike 0:VPN-X:VPN-X: chosen to populate IKE_SA traffic-selectors
2023-04-11 04:56:37.596980 ike 0:VPN-X: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation
2023-04-11 04:56:37.597104 ike 0:VPN-X:10635: out 85856F5AECE46AF50000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500000211016973BEEE810A1B1F71EC27D38C5BA0D57965A1A96261535D9F47A9FDEF82FEF40E0FAD754F9D4902A6E5C6E931A3CDCAB271784D3B6DC96D3DE2F6DC82DF1125E6C177517E2EEA7AD8CB7293A352D24DABE53BA59F52F32CDE78838BB46931D5A482DE21075AE67A935BD5F9AFA63B80650F4E25AF264A1A836D19A68E6801D172BC8B7AC542F691480886239909E5ED122DC4178AC0DF033233AD8868A95E4E7B6670B3E78DBD1F0F2F47C5D033B800E8325AEEEDEAD931FD9FC355A729000014AA392F42722E8928FCBB60E98FA6D2AF2900001C00004004F14FD9F49EDF9D86D7F4021DA302B06AF81640E80000001C0000400527DD2E55E4AA827CD6A87CA6CCC89355346B4718
2023-04-11 04:56:37.597302 ike 0:VPN-X:10635: sent IKE msg (SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=85856f5aece46af5/0000000000000000
2023-04-11 04:56:43.606883 ike 0:VPN-X:10635: out 85856F5AECE46AF50000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500000211016973BEEE810A1B1F71EC27D38C5BA0D57965A1A96261535D9F47A9FDEF82FEF40E0FAD754F9D4902A6E5C6E931A3CDCAB271784D3B6DC96D3DE2F6DC82DF1125E6C177517E2EEA7AD8CB7293A352D24DABE53BA59F52F32CDE78838BB46931D5A482DE21075AE67A935BD5F9AFA63B80650F4E25AF264A1A836D19A68E6801D172BC8B7AC542F691480886239909E5ED122DC4178AC0DF033233AD8868A95E4E7B6670B3E78DBD1F0F2F47C5D033B800E8325AEEEDEAD931FD9FC355A729000014AA392F42722E8928FCBB60E98FA6D2AF2900001C00004004F14FD9F49EDF9D86D7F4021DA302B06AF81640E80000001C0000400527DD2E55E4AA827CD6A87CA6CCC89355346B4718
Can you please help.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
There is an error message below:
2023-04-11 04:56:37.596980 ike 0:VPN-ATS: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation
I would recommend to check whether phase1 configuration is matching on IPsec peers and remote gateways are correct.
Hello,
We've made sure it's the same configuration.
Could it be because we're using 2 different firewalls?
Best regards,
Hello,
Fortigate supports the VPN connection with the Cisco ASA, in the VPN creation wizard you have the option to select the remote device type Cisco.
Although you cross-checked and found that the setup is the same, the debug logs indicate that IKE SA is not matching. For testing purposes, you can try using the remote device as Cisco in the VPN creation wizard to create a new tunnel.
BR
Rakesh
Yeah .. seems issue is because wrong phase 1 parameters. Please verify the phase1 settings at both end.
no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation
You posted the whole stuff.
Find The solution here
in phase 1 is a wrong parameter as I have already been informed.
Hi,
Can you please check phase1 settings on both side of tunnels. Based on debugs, it seems there's a mismatch in phase1 settings.
ref output:
2023-04-11 04:56:37.596860 ike 0:VPN-X:VPN-X: chosen to populate IKE_SA traffic-selectors
2023-04-11 04:56:37.596980 ike 0:VPN-X: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation
Also, please check if DPD is enabled on both the ends.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.