Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pkc
New Contributor

site to site with cisco asa - Unknown SPI

Hi,

 

I'm stuck while trying to have a vpn site to site work between my fortigate vm 04 running 5.2.4 and a cisco asa device.

 

The vpn ends on a VDOM on a loopback.

 

I checked the parameters several times, phase1 and phase2 are correct, but when the remote site sends traffic, the fortigate

drops it with "unknown spi " showing the spi ID that is listed when I list the active phase 2 tunnels. 

 

Cisco device shows correct phase1 and phase2, but traffic is still dropped. 

 

Is there a known issue related to fortios 5.2.4 and cisco asa ?

 

Are there some incompatibilities ?

 

thanks.

 

 

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors