cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
479
Views
0
Helpful
2
Replies

Unable to establish IPsec tunnel with Fortigate firewall

alantan
Level 1
Level 1

Hi All,

Anyone can help look into this attach log which failure to establish the site to site tunnel with fortigate firewall appliances. Any idea standard guideline can be follow  peering tunnel with third parties firewall as mentioned ?

2 Replies 2

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

As per the logs we see QM FSM errors that means Phase 2 settings are not matching on both the peers.

Can you please validate the same?

Phase 2 settings include your transform set, access-list for interesting traffic and PFS setting (if enabled)

Regards,

Aditya

Please rate helpful and mark correct answers

zaydiip
Level 1
Level 1

Hi Alantan,

You have to enable PFS on Cisco side