Hi @quynhln8 ,
Have you run the command below as previously suggested? Have you spotted any mismatch?
diagnose vpn ike log-filter dst-addr4 <remote-peer-IP>
diagnose debug application ike -1
diagnose debug console timestamp enable
diagnose debug enable
Note: Starting from FortiOS 7.4.1, the 'diagnose vpn ike log-filter dst-addr4' command has been changed to 'diagnose vpn ike log filter rem-addr4'.
If you can, please paste its output here. If you cannot paste it, I would suggest you to open a ticket with our support so this issue can be properly investigated.
Best regards,
Hi @quynhln8,
It shows that they have different phase2-selectors; kindly match their phase2-selector and do not add it at once as the SPI will be different.
Kindly see this document for further information.
tks every one, it's already working
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.