Hi all,
I have some big problems with mit Fortigate 300A on site A and our Cisco SRP521W on site B.
We cant establish an site to site vpn connection...
phase 1 looks good, but phase 2 didnt work... sometimes (~in summary 5,6 times) I get an error " no matching gateway for new request" for phase 2. but at the moment I dont get ANY error? I can only see the success messages from phase 1... and then nothin happen?
log from fortigate:
ike 0: comes 46.206.xxx.xxx:500->192.168.1.1:500,ifindex=5....
ike 0: IKEv1 exchange=Aggressive id=8752b1e752eef59d/0000000000000000 len=268
ike 0: found vpn_xxx_grz 192.168.1.1 5 -> 46.206.xxx.xxx:500
ike 0:vpn_xxx_grz:23191: responder: aggressive mode get 1st message...
ike 0:vpn_xxx_grz:23191: VID DPD AFCAD71368A1F1C96B8696FC77570100
ike 0:vpn_xxx_grz:23191: negotiation result
ike 0:vpn_xxx_grz:23191: proposal id = 1:
ike 0:vpn_xxx_grz:23191: protocol id = ISAKMP:
ike 0:vpn_xxx_grz:23191: trans_id = KEY_IKE.
ike 0:vpn_xxx_grz:23191: encapsulation = IKE/none
ike 0:vpn_xxx_grz:23191: type=OAKLEY_ENCRYPT_ALG, val=3DES_CBC.
ike 0:vpn_xxx_grz:23191: type=OAKLEY_HASH_ALG, val=MD5.
ike 0:vpn_xxx_grz:23191: type=AUTH_METHOD, val=PRESHARED_KEY.
ike 0:vpn_xxx_grz:23191: type=OAKLEY_GROUP, val=1024.
ike 0:vpn_xxx_grz:23191: ISKAMP SA lifetime=28800
ike 0:vpn_xxx_grz:23191: cookie 8752b1e752eef59d/2014dbacd5096597
ike 0:vpn_xxx_grz:23191: ISAKMP SA 8752b1e752eef59d/2014dbacd5096597 key 24:241ABB3CB5099BA10057E4DD5F59C827954DBBF16BE754AE
ike 0:vpn_xxx_grz:23191: sent IKE msg (agg_r1send): 192.168.1.1:500->46.206.xxx.xxx:500, len=288
ike 0: comes 46.206.xxx.xxx:500->192.168.1.1:500,ifindex=5....
ike 0: IKEv1 exchange=Informational id=8752b1e752eef59d/0000000000000000 len=40
ike 0: found vpn_xxx_grz 192.168.1.1 5 -> 46.206.xxx.xxx:500
ike 0:vpn_xxx_grz: ISAKMP SA 8752b1e752eef59d/0000000000000000 not found for informational msg from 46.206.xxx.xxx
ike 0:vpn_xxx_grz:23193: sent IKE msg (P1_RETRANSMIT): 192.168.1.1:500->46.206.xxx.xxx:500, len=288
ike 0: comes 46.206.xxx.xxx:500->192.168.1.1:500,ifindex=5....
ike 0: IKEv1 exchange=Informational id=71f51e9eed28fcf8/0000000000000000 len=40
ike 0: found vpn_xxx_grz 192.168.1.1 5 -> 46.206.xxx.xxx:500
ike 0:vpn_xxx_grz: ISAKMP SA 71f51e9eed28fcf8/0000000000000000 not found for informational msg from 46.206.xxx.xxx
ppppppllllzzzzz anyone can help me?
THANKS A LOT !