IPsec VPN Troubleshooting PDF
IPsec VPN Troubleshooting PDF
IPsec VPN Troubleshooting PDF
This section contains tips to help you with some common challenges of IPsec VPNs.
The options to configure policy-based IPsec VPN are unavailable.
Go to System > Config > Features. Select Show More and turn on Policy-based IPsec VPN.
Remove any Phase 1 or Phase 2 configurations that are not in use. If a duplicate instance of the VPN
tunnel appears on the IPsec Monitor, reboot your FortiGate unit to try and clear the entry.
If you are still unable to connect to the VPN tunnel, run the diagnostic command in the CLI:
diag debug application ike -1
diag debug enable
The resulting output may indicate where the problem is occurring. When you are finished, disable the
diagnostics by using the following command:
diag debug reset
diag debug disable