Hi All,
I am having trouble transmitting traffic across a VPN I have configured.
The remote end device is not an fortigate and there is bit of a language barrier with the engineer on that side.
On my end the VPN shows as down, and generating the specified traffic does not bring it up.
If I manually click the "Bring UP" button it shows as up but I am still unable to send traffic across it.
On the far end the engineer is reporting that Phase-1 is up, but not Phase-2.
Doing a debug on my fortigate I see this:
2017-01-25 13:28:34 ike 13:HNK-P1: ignoring IKE request, interface is administratively down 2017-01-25 13:28:34 ike 13:f16e4e6116823a62/0000000000000000:3580246: negotiation failure 2017-01-25 13:28:34 ike Negotiate ISAKMP SA Error: 2017-01-25 13:28:34 ike 13:f16e4e6116823a62/0000000000000000:3580246: no SA proposal chosen
I am not able to find any informations on the 1st line, but i can confirm all the interfaces on the VDOM are up.
On the 3rd line I can confirm there are policies applied to both the incoming and outgoing direction and I am even seeing hits on the outgoing side.
Any guidance will be highly appreciated.
Thanks,
Luwellan
Ok managed to resolve this issue, there was an mismatch on the quite mode selectors during phase 2, i.e. Local/Remote Address mismatch between the 2 points.
Traffic is not passing correctly, but funny thing is that I am still seeing the same "error" messages as mentioned i my previous post...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.