Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

delete_phase1_sa Error

Can anyone explain this error to me and how I can get rid of it. It comes up in the event log of the Fortigate-200 v2.8 when I try to make a vpn connection delete_phase1_sa Thanks
5 REPLIES 5
Not applicable

the phase1 will be deleted on phase2 failure..
Not applicable

Thanks for the reply... but can you please explain it to me in more detail and maybe suggest a fix. Thanks
Not applicable

Hi i can say you what you can review: -check that the proposal (encryption, lifetime, dh group) for the IKE 2nd phase match each other and try to switch off any keepalives/pings or dead peer detection on the Fortinet for both IKE modes. -check the IP settings (remote lan, local lan), they also affect the 2nd phase SA and must correspond to the Fortinet settings/selectors. try to enable some debugging on the fortinet: diag debug ena; diag debug application ike 2 or try to sniff some packet diag sniffer packet wanX ' proto 50 || port 500' bye
Not applicable

Thank you for the help.
mikelportu
New Contributor

Hi, same error here.I would like to know what caused the error and how you solved it.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors