Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ncaridi
New Contributor

VPN : Site 2 Site , 2 Wans

Hello Experts , 

 

I have a FGT90D on Site A  (only WAN1)

and a Fortigate 60D on Site B (WAN1 , WAN2) 

 

When I setup a IPSEC between Site A(90D) to Site B (60D) 

everything works fine on WAN1 to WAN1 but when setup a tunnel on WAN2 interface SiteB -60D to Site A 

the tunnel won't come up . looking at the logs I see the following error :

IPsec Phase1 Error 

peer SA proposal not match local policy

 

This is how I tested : 

1. Created a working tunnel on both fgt. wan1 to wan1 (tunnel is up) 

2. switched interface on fgt60 from wan1 to wan2. 

3. switched destination IP on fgt90d to wan2 ip address. 

 

since all other settings worked fine I assume it's the change from wan1 to wan2 on fgt60d. 

 

 

Any help on how to go about this is much appreciated. 

 

Thanks you , 

 

-NC. 

 

 

 

0 REPLIES 0
Labels
Top Kudoed Authors