This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Error VPN site to site ipsec from Sophos SG230 to Fortigate

Dear All,

Please help me, i setup VPN site to site ipsec from Sophos SG230 (UTM 9.509-3) to Fortigate. But error:

"

2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: added connection description "S_VPN_Ipsec_forti"
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #10: initiating Main Mode
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #10: received Vendor ID payload [RFC 3947]
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #10: received Vendor ID payload [Dead Peer Detection]
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #10: enabling possible NAT-traversal with method 3
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #10: NAT-Traversal: Result using RFC 3947: no NAT detected
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #10: Peer ID is ID_IPV4_ADDR: '192.168.10.1'
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #10: Dead Peer Detection (RFC 3706) enabled
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #10: ISAKMP SA established
2018:05:31-16:07:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #11: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP {using isakmp#10}
2018:05:31-16:08:34 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #11: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:08:34 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #11: starting keying attempt 2 of an unlimited number
2018:05:31-16:08:34 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #12: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #11 {using isakmp#10}
2018:05:31-16:09:44 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #12: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:09:44 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #12: starting keying attempt 3 of an unlimited number
2018:05:31-16:09:44 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #13: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #12 {using isakmp#10}
2018:05:31-16:10:54 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #13: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:10:54 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #13: starting keying attempt 4 of an unlimited number
2018:05:31-16:10:54 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #14: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #13 {using isakmp#10}
2018:05:31-16:12:04 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #14: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:12:04 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #14: starting keying attempt 5 of an unlimited number
2018:05:31-16:12:04 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #15: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #14 {using isakmp#10}
2018:05:31-16:13:14 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #15: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:13:14 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #15: starting keying attempt 6 of an unlimited number
2018:05:31-16:13:14 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #16: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #15 {using isakmp#10}
2018:05:31-16:14:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #16: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:14:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #16: starting keying attempt 7 of an unlimited number
2018:05:31-16:14:24 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #17: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #16 {using isakmp#10}
2018:05:31-16:15:34 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #17: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:15:34 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #17: starting keying attempt 8 of an unlimited number
2018:05:31-16:15:34 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #18: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #17 {using isakmp#10}
2018:05:31-16:16:44 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #18: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:16:44 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #18: starting keying attempt 9 of an unlimited number
2018:05:31-16:16:44 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #19: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #18 {using isakmp#10}
2018:05:31-16:17:54 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #19: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:17:54 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #19: starting keying attempt 10 of an unlimited number
2018:05:31-16:17:54 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #20: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #19 {using isakmp#10}
2018:05:31-16:19:04 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #20: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:19:04 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #20: starting keying attempt 11 of an unlimited number
2018:05:31-16:19:04 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #21: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #20 {using isakmp#10}
2018:05:31-16:20:14 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #21: max number of retransmissions (2) reached STATE_QUICK_I1. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
2018:05:31-16:20:14 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #21: starting keying attempt 12 of an unlimited number
2018:05:31-16:20:14 sophossg230_nmkl pluto[6009]: "S_VPN_Ipsec_forti" #22: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #21 {using isakmp#10}"

Thanks,

Best regards!!!



This thread was automatically locked due to age.
Parents
  • Chào Dao and welcome to the UTM Community!

    Please show pictures of the Edits of the IPsec Connection and the Remote Gateway.  Also confirm that both sides have selected DPD.

    I'm a little confused by the log portion above.  Please try the following:

    1. Confirm that Debug is not enabled.
    2. Disable the IPsec Connection.
    3. Start the IPsec Live Log and wait for it to begin to populate.
    4. Enable the IPsec Connection.
    5. Show us about 60 lines from enabling through the error.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Chào Dao and welcome to the UTM Community!

    Please show pictures of the Edits of the IPsec Connection and the Remote Gateway.  Also confirm that both sides have selected DPD.

    I'm a little confused by the log portion above.  Please try the following:

    1. Confirm that Debug is not enabled.
    2. Disable the IPsec Connection.
    3. Start the IPsec Live Log and wait for it to begin to populate.
    4. Enable the IPsec Connection.
    5. Show us about 60 lines from enabling through the error.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data