Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
domisawadogo
New Contributor

VPN Progress IPsec phase 2 ISSU

My VPN is UP. but at the log level I have a mistake   Progress IPsec phase 2 Action negotiate Status failure Result ERROR

5 REPLIES 5
Toshi_Esumi
Esteemed Contributor III

You need to provide enough info for anyone to understand what your VPN is. Site-to-site or remote access? Do you have multiple phase2s or just one? What is the selectors in phase2s? copy&paste&mask-some-IDs of phase1-interface and phase2-interface into the thread is the best.

domisawadogo
New Contributor

it is a VPN SITE to SITE with two phase. It's between fortigate-cisco how much of a phase should I do?

Toshi_Esumi
Esteemed Contributor III

IPSec (w/ IKEv1) always have two phases, phase1 and phase2. I was asking if you have muiltpke phase2-interfaces configured to have multiple traffic selectors. The default is 0/0 <-> 0/0 means all. If you go to "config vpn ipsec phase2-interface" in CLI then "show" would show you all phase2s you configured.

And you said "UP", but is it actually passing traffic site-to-site?

domisawadogo

the tunnel goes to UP. but I have an error for phase two

 

ActionnegotiateStatusfailureResultERROR
Toshi_Esumi
Esteemed Contributor III

Check phase2-interface config on FG and ACL you created&used for phase2 on Cisco. They need to match (mirrored).

Labels
Top Kudoed Authors