Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Stéphane
New Contributor

VPN issue "negotiation timeout, deleting - connection expiring due to phase1 down"

Hello,

 

I have many VPN tunnels configured with the same settings

Some of them are down and some are up

The link monitor status is alive

The diagnose debug application ike -1 command shows a negotiation timeout in the phase 1

Does someone have an idea about the root cause?

Thanks for your help

 

S.

3 REPLIES 3
Stéphane
New Contributor

Issue due to configuration mismatch between peers...

Stemjay

hi Stephane, iam experiencing a similar challenge are you able to share the parameters that were mimatched or steps taken to resolve

dbu
Staff
Staff

Hello,

 

Negotiation timeout can happen for many reasons. 

Did it ever work for those clients ?  Or is the issue intermittent? 

If Not,Are those peers same type devices ? What vendor/client?


I believe  best next action is to take a packet capture. Definitely a packet capture can show you more  information on what packets are sent and received.

You can run also the debug " diagnose debug application ike -1"

 

Regards!

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors