Learn how to a build a cloud-first strategyRegister Now


IPsec Tunnel on Fortigate not working

Posted on 2011-10-12
Medium Priority
Last Modified: 2012-06-27

The IPsec tunnel on the Fortigate box is not working properly. It was working before and nothing has changed on the network. I have checked the logs on the dial up client (Fortigate box), I get the following message:

Initiator: parsed aggressive mode message # 1 (error)
Negotiate SA Error: probable pre-shared secret mismatch

On the Server (Fortigate box) the log is giving me this message:

Responder: parsed main mode message # 3 (error)
How can I make the tunnel go up again?

On the Server
Question by:alee0786
  • 2
  • 2
LVL 14

Accepted Solution

theruck earned 1000 total points
ID: 36954468
setup the tunell from scratch? probable pre-shared secret mismatch
it is never "nothing has changed"
check if both sides are set to aggressive mode or try to change the authentication algorythms

Author Comment

ID: 36954500
OK, I have setup the tunnel from scratch almost 6-7 time already but same result. On the Server logs I am getting the following:

Received error notification from Peer: Invalid Hash Information.

I have checked and it is set to aggressive mode.
LVL 14

Expert Comment

ID: 36954512
that means in general that the passwords do not match. chek your passwords if they are the same or if they are not too long

Author Comment

ID: 36954793
Now I tried setting it up to different authentication algorithm and it started working.

So far so good, it is holding up.

Thanks a lot.  
LVL 71

Expert Comment

ID: 37158158
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So, if your PC is old or new and it does not boot or has no display then what do you do? Precautions : -During connecting or disconnecting devices, be sure to have the AC electrical power disconnected -Temporarily ground yourself, or use a wris…
On September 18, Experts Exchange launched the first installment of the Help Bell, a new feature for Premium Members, Team Accounts, and Qualified Experts. The Help Bell will serve as an additional tool to help teams increase question visibility.
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …
Suggested Courses

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question