cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
424
Views
0
Helpful
1
Replies

[Site-to-Site] Phase-2 is not proceeded

BAEK_1027
Level 1
Level 1

Hi, I tried to set Site to Site with FortiGate VPN.

However, I wonder why it is not proceeded Phase-2 as follows.

Can you check it please?

 

 

phase-2.gif

 

 

11.PNG222.PNG

 

 

111.png2222.png333.png444.png5555.png

 

crypto map outside_map 21 match address outside_cryptomap_21
crypto map outside_map 21 set pfs
crypto map outside_map 21 set peer 13.125.160.32
crypto map outside_map 21 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map outside_map 21 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES
crypto map outside_map 22 match address outside_cryptomap_16
crypto map outside_map 22 set pfs
crypto map outside_map 22 set peer 219.250.188.2
crypto map outside_map 22 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map outside_map 22 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES
crypto map outside_map 23 match address outside_cryptomap_22
crypto map outside_map 23 set peer 194.245.91.15
crypto map outside_map 23 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map outside_map 24 match address outside_cryptomap_19
crypto map outside_map 24 set pfs group5
crypto map outside_map 24 set peer 27.1.253.142
crypto map outside_map 24 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map outside_map interface outside

vpn-tunnel-protocol ikev1 ikev2
group-policy GroupPolicy_27.1.253.142 internal
group-policy GroupPolicy_27.1.253.142 attributes

ikev1 pre-shared-key *****
tunnel-group 27.1.253.142 type ipsec-l2l
tunnel-group 27.1.253.142 general-attributes
default-group-policy GroupPolicy_27.1.253.142
tunnel-group 27.1.253.142 ipsec-attributes
ikev1 pre-shared-key *****
ikev2 remote-authentication pre-shared-key *****
ikev2 local-authentication pre-shared-key *****
!

 

1 Reply 1

marce1000
VIP
VIP

 

 - Checkout this example setup and or compare with your settings :

              https://www.youtube.com/watch?v=sqwHyKVMhFU

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '