Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
LECC
New Contributor

IPsec VPN problems

Hello,

Can someone help me find out a solution?

I'm trying to set up an IPsec VPN through internet, I can ping successfuly the two public IP but on the fortinet I get this logs:

 

 ike 0:IPSec_to_IPSN:IPSec_to_IPSN: IPsec SA connect 13 190.94.103.234->57.97.101.254:0 ike 0:IPSec_to_IPSN:IPSec_to_IPSN: using existing connection ike 0:IPSec_to_IPSN:IPSec_to_IPSN: config found ike 0:IPSec_to_IPSN: request is on the queue ike 0:IPSec_to_IPSN:24839: out 4C2DC551B571644683924C2954B5939F2E2023080000000100000160230001441D5A534417A47C5D8088428CE6E25D57CEEF007D9A162C80C0F938153270D752317A850ECB6BB7DAF40CA76761A221B4A467177C74A505B031FEC0C4B1D5C893E06D4138ECC10DF06D4B64D2DC26AA741D527EB7F9015FAA608BDAD72BF972E23286EE97985E62ADFFC651D128E91CE0ED4993A7303D1F191018D82879C6B0A7C265104EBE5C469F6DE30D1DAEB1113AFEED9844F6749738B0BC178B7A031B1510A8DDA08375DD9EAF44746DC61AF81D09F1848718E7A3DB730A7EBBC250EA553A33F381396F10FE1051BFC173F6787C1079E5BF82189A47FE46E57C17C4B3BF8DCE956F6266EC9EB23DBDD3BCE852D86A4BDED1AFDA027FCDD002560D90B6E4FB31DEF718CF03369A47D15ED685DF86CFC5719C31FBC6AB048C5ACCE68EA8416B356B2327B330EB2CD01CB2B22C3E002B8B08CB78EEF4E3D6B10C020E6C74CB ike 0:IPSec_to_IPSN:24839: sent IKE msg (RETRANSMIT_AUTH): 190.94.103.234:500->57.97.101.254:500, len=352, id=4c2dc551b5716446/83924c2954b5939f:00000001 ike 0: unknown SPI ac173ec2 13 57.97.101.254:0->190.94.103.234 ike 0: found IPSec_to_IPSN 190.94.103.234 13 -> 57.97.101.254:500 ike 0:IPSec_to_IPSN:24839:IPSec_to_IPSN:24996: ignoring unknown SPI ac173ec2, IPsec SA still negotiating------------------------------> ike 0:IPSec_to_IPSN:IPSec_to_IPSN: IPsec SA connect 13 190.94.103.234->57.97.101.254:0 ike 0:IPSec_to_IPSN:IPSec_to_IPSN: using existing connection ike 0:IPSec_to_IPSN:IPSec_to_IPSN: config found ike 0:IPSec_to_IPSN: request is on the queue ike shrank heap by 122880 bytes ike 0: unknown SPI ac173ec2 13 57.97.101.254:0->190.94.103.234 ike 0: found IPSec_to_IPSN 190.94.103.234 13 -> 57.97.101.254:500 ike 0:IPSec_to_IPSN:24839:IPSec_to_IPSN:24996: ignoring unknown SPI ac173ec2, IPsec SA still negotiating---------------------------> ike 0:IPSec_to_IPSN:24839: negotiation timeout, deleting ike 0:IPSec_to_IPSN: connection expiring due to phase1 down ike 0:IPSec_to_IPSN: deleting ike 0:IPSec_to_IPSN: deleted

1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

Is this IKEv2? You probably need to run debugging on the other end then compare the debug output. The other side might not be receiving what this side is sending out, or not understanding. My guess is the other side is not a FGT. Something in the config might be mismatching. One direction seems to be fine but the other direction doesn't.

Labels
Top Kudoed Authors