Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sw2090
SuperUser
SuperUser

strange behavior on ipsec vpn

Following constellation:

 

FortiGate with FOS 7.2.10

FortiClient 7.2.5 on windows.

 

IPsec tunnel witb psk and xauth against ldap usergroup on Authenticator and mode config.

 

Behavior:

- Tunnel connects

- does psk auth and proposals

- does mode config - gets ip and everything

- initates xauth

- fgt send xauth request to client

 

Log on FGT reports "Client has not completet xauth challenge" even before the forticlient prompts me for 2nd factor.

Looks like FGT sends the xauth request but does not wait for an answer from client.

 

Do you have any suggestions?

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
1 REPLY 1
abarushka
Staff
Staff

Hello,

 

I would recommend to collect debug traces below while the issue is reproduced:

 

diagnose debug application fnbamd -1
diagnose debug application ike -1
diagnose debug enable

 

Moreover, I would also recommend to check FortiClient logs.

FortiGate
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors