Hot!IPsec VPN problems

Author
LECC
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/08/11 12:19:05
  • Status: offline
2020/08/11 17:52:02 (permalink)
0

IPsec VPN problems

Hello,
Can someone help me find out a solution?
I'm trying to set up an IPsec VPN through internet, I can ping successfuly the two public IP but on the fortinet I get this logs:
 
 ike 0:IPSec_to_IPSN:IPSec_to_IPSN: IPsec SA connect 13 190.94.103.234->57.97.101.254:0
ike 0:IPSec_to_IPSN:IPSec_to_IPSN: using existing connection
ike 0:IPSec_to_IPSN:IPSec_to_IPSN: config found
ike 0:IPSec_to_IPSN: request is on the queue
ike 0:IPSec_to_IPSN:24839: out 4C2DC551B571644683924C2954B5939F2E2023080000000100000160230001441D5A534417A47C5D8088428CE6E25D57CEEF007D9A162C80C0F938153270D752317A850ECB6BB7DAF40CA76761A221B4A467177C74A505B031FEC0C4B1D5C893E06D4138ECC10DF06D4B64D2DC26AA741D527EB7F9015FAA608BDAD72BF972E23286EE97985E62ADFFC651D128E91CE0ED4993A7303D1F191018D82879C6B0A7C265104EBE5C469F6DE30D1DAEB1113AFEED9844F6749738B0BC178B7A031B1510A8DDA08375DD9EAF44746DC61AF81D09F1848718E7A3DB730A7EBBC250EA553A33F381396F10FE1051BFC173F6787C1079E5BF82189A47FE46E57C17C4B3BF8DCE956F6266EC9EB23DBDD3BCE852D86A4BDED1AFDA027FCDD002560D90B6E4FB31DEF718CF03369A47D15ED685DF86CFC5719C31FBC6AB048C5ACCE68EA8416B356B2327B330EB2CD01CB2B22C3E002B8B08CB78EEF4E3D6B10C020E6C74CB
ike 0:IPSec_to_IPSN:24839: sent IKE msg (RETRANSMIT_AUTH): 190.94.103.234:500->57.97.101.254:500, len=352, id=4c2dc551b5716446/83924c2954b5939f:00000001
ike 0: unknown SPI ac173ec2 13 57.97.101.254:0->190.94.103.234
ike 0: found IPSec_to_IPSN 190.94.103.234 13 -> 57.97.101.254:500
ike 0:IPSec_to_IPSN:24839:IPSec_to_IPSN:24996: ignoring unknown SPI ac173ec2, IPsec SA still negotiating------------------------------>
ike 0:IPSec_to_IPSN:IPSec_to_IPSN: IPsec SA connect 13 190.94.103.234->57.97.101.254:0
ike 0:IPSec_to_IPSN:IPSec_to_IPSN: using existing connection
ike 0:IPSec_to_IPSN:IPSec_to_IPSN: config found
ike 0:IPSec_to_IPSN: request is on the queue
ike shrank heap by 122880 bytes
ike 0: unknown SPI ac173ec2 13 57.97.101.254:0->190.94.103.234
ike 0: found IPSec_to_IPSN 190.94.103.234 13 -> 57.97.101.254:500
ike 0:IPSec_to_IPSN:24839:IPSec_to_IPSN:24996: ignoring unknown SPI ac173ec2, IPsec SA still negotiating--------------------------->
ike 0:IPSec_to_IPSN:24839: negotiation timeout, deleting
ike 0:IPSec_to_IPSN: connection expiring due to phase1 down
ike 0:IPSec_to_IPSN: deleting
ike 0:IPSec_to_IPSN: deleted
#1

1 Reply Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 2339
    • Scores: 227
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: online
    Re: IPsec VPN problems 2020/08/11 22:45:35 (permalink)
    0
    Is this IKEv2? You probably need to run debugging on the other end then compare the debug output. The other side might not be receiving what this side is sending out, or not understanding. My guess is the other side is not a FGT. Something in the config might be mismatching. One direction seems to be fine but the other direction doesn't.
    #2
    Jump to:
    © 2020 APG vNext Commercial Version 5.5