Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN IPSec Site to Site will not connect "selected peer config XXX-1' inacceptable: constraint checking failed"

Hello,

i try since three days to build up ipsec site to site vpn.

I see the following error when trying to Setup a VPN Connection between the XG and a different vendor Firewall (fortigate). Parameters (Phase 1 + Phase 2) are checked three times with the other site. Also used sophos <-> fortigate onepager.

[IKE] <XXX-1|6948> authentication of 'X.X.X.X' with pre-shared key successful
[CFG] <XXX-1|6948> constraint check failed: identity 'X.X.X.X' required
[CFG] <XXX-1|6948> selected peer config XXX-1' inacceptable: constraint checking failed
[CFG] <XXX-1|6948> no alternative config found
[DMN] <XXX-1|6948> [GARNER-LOGGING] (child_alert) ALERT: peer authentication failed
[ENC] <XXX-1|6948> generating INFORMATIONAL request 2 [ N(AUTH_FAILED) ]

Using Pre-Shared Key and have my Local ID and Remote ID type blank.

Any Advice?

Thanks



This thread was automatically locked due to age.
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?