Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SidiMamoun
New Contributor

VPN Site to Site expired due to phase 1 down

Hello,

I have a problem with establishing a site to site VPN, we have fortigate 60E on our side and cisco ASA on partners side.

You'll find bellow the results of the debug:

2023-04-11 04:56:12.586859 ike 0:VPN-X:10634: out 7C4EE6958EB809940000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500007B8DC496C30E865C1796B8CAF210EB69BB3D59EBE2874CDAF4792857CA7B126D9038879AD02D883D3065C9771AE40D47429296C68E7CEF147BB00EE2B0CDA28C1981DD318990E91121329743D4B5464716E8C288CCDDA5CE6D031E2F29C742EBDBB3FB70DFD9C1EACAF7002F9FB8C52085A83D10076826C0E1047C93EEB9255DB9DC91963B18B921E8602C785E908E2B223A713265CCBBF1A9633CD3B8260EBFF71A7A83AE96079D61C0E18ED4AE531213456D97E785BA948874D024E12A71DB29000014F9300D4BEE615BF91D43479DF27CC3082900001C00004004FA471070E89A907177FAAE1E9AAA8B9320649CD70000001C0000400566197531D175933B8640C0E6AE2033C179E31A60

2023-04-11 04:56:12.587079 ike 0:VPN-X:10634: sent IKE msg (RETRANSMIT_SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=7c4ee6958eb80994/0000000000000000

2023-04-11 04:56:15.576877 ike shrank heap by 122880 bytes

2023-04-11 04:56:24.596856 ike 0:VPN-X:10634: out 7C4EE6958EB809940000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500007B8DC496C30E865C1796B8CAF210EB69BB3D59EBE2874CDAF4792857CA7B126D9038879AD02D883D3065C9771AE40D47429296C68E7CEF147BB00EE2B0CDA28C1981DD318990E91121329743D4B5464716E8C288CCDDA5CE6D031E2F29C742EBDBB3FB70DFD9C1EACAF7002F9FB8C52085A83D10076826C0E1047C93EEB9255DB9DC91963B18B921E8602C785E908E2B223A713265CCBBF1A9633CD3B8260EBFF71A7A83AE96079D61C0E18ED4AE531213456D97E785BA948874D024E12A71DB29000014F9300D4BEE615BF91D43479DF27CC3082900001C00004004FA471070E89A907177FAAE1E9AAA8B9320649CD70000001C0000400566197531D175933B8640C0E6AE2033C179E31A60

2023-04-11 04:56:24.597050 ike 0:VPN-X:10634: sent IKE msg (RETRANSMIT_SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=7c4ee6958eb80994/0000000000000000

2023-04-11 04:56:36.586845 ike 0:VPN-X:10634: negotiation timeout, deleting

2023-04-11 04:56:36.589409 ike 0:VPN-X: connection expiring due to phase1 down

2023-04-11 04:56:36.589449 ike 0:VPN-X: deleting

2023-04-11 04:56:36.589471 ike 0:VPN-X: flushing

2023-04-11 04:56:36.589651 ike 0:VPN-X: flushed

2023-04-11 04:56:36.589714 ike 0:VPN-X: deleted

2023-04-11 04:56:36.589741 ike 0:VPN-X: schedule auto-negotiate

2023-04-11 04:56:37.596860 ike 0:VPN-X:VPN-X: chosen to populate IKE_SA traffic-selectors

2023-04-11 04:56:37.596980 ike 0:VPN-X: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation

2023-04-11 04:56:37.597104 ike 0:VPN-X:10635: out 85856F5AECE46AF50000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500000211016973BEEE810A1B1F71EC27D38C5BA0D57965A1A96261535D9F47A9FDEF82FEF40E0FAD754F9D4902A6E5C6E931A3CDCAB271784D3B6DC96D3DE2F6DC82DF1125E6C177517E2EEA7AD8CB7293A352D24DABE53BA59F52F32CDE78838BB46931D5A482DE21075AE67A935BD5F9AFA63B80650F4E25AF264A1A836D19A68E6801D172BC8B7AC542F691480886239909E5ED122DC4178AC0DF033233AD8868A95E4E7B6670B3E78DBD1F0F2F47C5D033B800E8325AEEEDEAD931FD9FC355A729000014AA392F42722E8928FCBB60E98FA6D2AF2900001C00004004F14FD9F49EDF9D86D7F4021DA302B06AF81640E80000001C0000400527DD2E55E4AA827CD6A87CA6CCC89355346B4718

2023-04-11 04:56:37.597302 ike 0:VPN-X:10635: sent IKE msg (SA_INIT): X.X.X.X:500->X.X.X.X:500, len=352, id=85856f5aece46af5/0000000000000000

2023-04-11 04:56:43.606883 ike 0:VPN-X:10635: out 85856F5AECE46AF50000000000000000212022080000000000000160220000300000002C010100040300000C0100000C800E01000300000802000005030000080300000C0000000804000005280000C8000500000211016973BEEE810A1B1F71EC27D38C5BA0D57965A1A96261535D9F47A9FDEF82FEF40E0FAD754F9D4902A6E5C6E931A3CDCAB271784D3B6DC96D3DE2F6DC82DF1125E6C177517E2EEA7AD8CB7293A352D24DABE53BA59F52F32CDE78838BB46931D5A482DE21075AE67A935BD5F9AFA63B80650F4E25AF264A1A836D19A68E6801D172BC8B7AC542F691480886239909E5ED122DC4178AC0DF033233AD8868A95E4E7B6670B3E78DBD1F0F2F47C5D033B800E8325AEEEDEAD931FD9FC355A729000014AA392F42722E8928FCBB60E98FA6D2AF2900001C00004004F14FD9F49EDF9D86D7F4021DA302B06AF81640E80000001C0000400527DD2E55E4AA827CD6A87CA6CCC89355346B4718

 

 

Can you please help.

 

7 REPLIES 7
abarushka
Staff
Staff

Hello,

 

There is an error message below:

2023-04-11 04:56:37.596980 ike 0:VPN-ATS: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation

 

I would recommend to check whether phase1 configuration is matching on IPsec peers and remote gateways are correct.

FortiGate
SidiMamoun

Hello,

 

We've made sure it's the same configuration.

Could it be because we're using 2 different firewalls?

 

Best regards,

rtichkule

Hello,

 

Fortigate supports the VPN connection with the Cisco ASA, in the VPN creation wizard you have the option to select the remote device type Cisco.

 

Although you cross-checked and found that the setup is the same, the debug logs indicate that IKE SA is not matching. For testing purposes, you can try using the remote device as Cisco in the VPN creation wizard to create a new tunnel.

 

BR

Rakesh

rosatechnocrat
Contributor II

Yeah .. seems issue is because wrong phase 1 parameters. Please verify the phase1 settings at both end. 

 

no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation

 

 

Rosa Technocrat --

Also on YouTube---

Please do Subscribe
Rosa Technocrat --Also on YouTube---Please do Subscribe
faris12
New Contributor

You posted the whole stuff.

Find The solution here

Christian_89
Contributor III

in phase 1 is a wrong parameter as I have already been informed.

mgoswami
Staff
Staff

Hi,

 

Can you please check phase1 settings on both side of tunnels. Based on debugs, it seems there's a mismatch in phase1 settings.

ref output:

2023-04-11 04:56:37.596860 ike 0:VPN-X:VPN-X: chosen to populate IKE_SA traffic-selectors

2023-04-11 04:56:37.596980 ike 0:VPN-X: no suitable IKE_SA, queuing CHILD_SA request and initiating IKE_SA negotiation

 

Also, please check if DPD is enabled on both the ends.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors