Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ahmetyilmaz
New Contributor

IPSEC Fail

Hi All,

 

Some ip trying to connect over ipsec tunnel to our network. Why can't block IPS these?

 

Like this:

 

Message meets Alert condition

date=2020-09-08 time=06:51:12 devname=xxxxxxxx devid=xxxxxxxxxxx logid="0101037128" type="event" subtype="vpn" level="error" vd="root" eventtime=1599537072204809801 tz="+0300" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=216.218.206.78 locip=xxxxxxxx remport=23703 locport=500 outintf="wan1" cookies="3e35c70729dfedef/0000000000000000" user="N/A" group="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="N/A" status="failure" init="remote" mode="main" dir="inbound" stage=1 role="responder" result="ERROR"

3 REPLIES 3
Markus
Valued Contributor

Hello and welcome to the forums. In short: Because of how the FG handles connections (IPS is involved later) in the flow https://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-life-of-packet-52/LoP-packet-flo... You have to deal with local in policies, if you want to block such IPs (or regions etc.) https://forum.fortinet.com/tm.aspx?m=171342

 

Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
ahmetyilmaz

Thank you very much for reply Markus. I couldn't find before Packet flow.

Markus
Valued Contributor

glad to help


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
Labels
Top Kudoed Authors