cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
699
Views
0
Helpful
1
Replies

SA540 - IPSEC

kri.chi.85
Level 1
Level 1

Dear Team,

I have SA540 firewall with me, I am trying to enable a site-to-site VPN between Fortigate 50B and SA540. I am facing issues with the setup. Please say if any license is required for bringing uo the site to site IPSEC tunnel.

Please find the below error logs and the screen shoot generated while bringing up the tunnel in sa540:

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:  accept a request to establish IKE-SA: (Fortigate IP)

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:  Configuration found for (Fortigate IP).

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:  Configuration found for (Fortigate IP).

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:  Initiating new phase 1 negotiation: (SA540 IP)[500]<=>(Fortigate IP)[500]

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:  Beginning Identity Protection mode.

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:   [isakmp_ident.c:185]: XXX: NUMNATTVENDORIDS: 3

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:   [isakmp_ident.c:189]: XXX: setting vendorid: 4

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:   [isakmp_ident.c:189]: XXX: setting vendorid: 8

Sat Dec 22 18:22:26 2012 (GMT +0530): [Cisco] [IKE] INFO:   [isakmp_ident.c:189]: XXX: setting vendorid: 9

Sat Dec 22 18:22:57 2012 (GMT +0530): [Cisco] [IKE] ERROR:  Invalid SA protocol type: 0

Sat Dec 22 18:22:57 2012 (GMT +0530): [Cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1.

Sat Dec 22 18:23:14 2012 (GMT +0530): [Cisco] [IKE] INFO:  Using IPsec SA configuration: 192.168.1.0/24<->192.168.15.0/24

Sat Dec 22 18:23:14 2012 (GMT +0530): [Cisco] [IKE] INFO:  Configuration found for (Fortigate IP).

Sat Dec 22 18:23:14 2012 (GMT +0530): [Cisco] [IKE] INFO:  Configuration found for (Fortigate IP).

Sat Dec 22 18:23:45 2012 (GMT +0530): [Cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP (Fortigate IP)->(SA540 IP)

Sat Dec 22 18:24:16 2012 (GMT +0530): [Cisco] [IKE] ERROR:  Phase 1 negotiation failed due to time up for (Fortigate IP)[500]. 367261e23cbb24a2:0000000000000000

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:  Using IPsec SA configuration: 192.168.1.0/24<->192.168.15.0/24

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:  Configuration found for (Fortigate IP).

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:  Configuration found for (Fortigate IP).

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:  Initiating new phase 1 negotiation: (SA540 IP)[500]<=>(Fortigate IP)[500]

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:  Beginning Identity Protection mode.

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:   [isakmp_ident.c:185]: XXX: NUMNATTVENDORIDS: 3

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:   [isakmp_ident.c:189]: XXX: setting vendorid: 4

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:   [isakmp_ident.c:189]: XXX: setting vendorid: 8

Sat Dec 22 18:24:27 2012 (GMT +0530): [Cisco] [IKE] INFO:   [isakmp_ident.c:189]: XXX: setting vendorid: 9

Sat Dec 22 18:24:58 2012 (GMT +0530): [Cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP (Fortigate IP)->(SA540 IP)

Sat Dec 22 18:25:27 2012 (GMT +0530): [Cisco] [IKE] INFO:  Using IPsec SA configuration: 192.168.1.0/24<->192.168.15.0/24

Sat Dec 22 18:25:27 2012 (GMT +0530): [Cisco] [IKE] INFO:  Configuration found for (Fortigate IP).

Sat Dec 22 18:25:27 2012 (GMT +0530): [Cisco] [IKE] INFO:  Configuration found for (Fortigate IP).

Thank you guys,

Chaitanya.G

1 Reply 1

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

I have never used the Small Business devices to be honest (not to mention Fortigate). I think they actually have their own section on these forums.

If you dont get any asnwers here you could consider posting there too  (link below)

https://supportforums.cisco.com/community/netpro/small-business

If I would have to guess on the basis of the log output it would seem that either the other end doesnt have any configuration related to this L2L VPN or the L2L VPN configurations exist but there is no matching Phase1 policy configured.

Is there any way to get some specific information about Phase1 negotiations on the SA540 device?

Is the remote device controlled by some other person or do you have management access to it too?

- Jouni

Review Cisco Networking for a $25 gift card