Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bripple89
New Contributor

IPSEC VPN - Site to Site Best Practices & Phase 1 errors.

Hey guys.

 

I've got a 5 locations with Fortigate 60E's in place. 2 of those locations are not on my MPLS ring. In order to reach internal servers within the MPLS - I create IPSec tunnels to a AT&T Public IP with only 500, 4500 ports open and it NAT's to my internal private IP of the Fortigate. 

 

I've got a tunnel created right now and it's up and passing traffic, however, it's still generating Phase 1 errors? The heck? I'm glad everything is working but it's driving me crazy that it's still generating errors! (Peer SA proposal not chosen is the error)

 

Also - What are you IPSec site to site best practices? Do you guys use the Wizard and the default templates or do you guys always do "Custom"? I've had some major issues with tunnels coming up and then no traffic passing through them these past couple of days and it's beyond frustrating. 

 

 I know I'm not providing any log details or very much information to go by but just curious if anyone has experienced these came kind of issues. 

 

Btw - All my Fortigate 60E's are running 5.6.6 (1630).

0 REPLIES 0
Labels
Top Kudoed Authors