pjhtech Tools
FortiGate

FortiGate “no proposal chosen”: IKE, ESP and DH Checks

Troubleshoot FortiGate proposal errors by tunnel selection, IKE/ESP transforms, PRF, DH, PFS and the failed negotiation stage.

If IKE debug reports no proposal chosen, first identify whether the failed exchange is IKE or a Child SA. Match the agreed proposal and DH/PFS values on both ends for that stage. If the message says does not match configuration address, use the gateway/VIP correction below instead.

Scope: FortiGate route-based IPsec; IKE and ESP proposal diagnosis.

Read the selected gateway and configured transforms

Run a single connection attempt with filtered IKE debug in the tunnel’s VDOM. Note the tunnel name attached to the failure and whether it occurs in SA_INIT, IKE_AUTH or a Child SA/rekey exchange. Then read:

Read-only • run in the tunnel’s VDOM
show full-configuration vpn ipsec phase1-interface "<existing-tunnel>"
show full-configuration vpn ipsec phase2-interface
diagnose vpn ike gateway list

Keep output private; it includes secrets or SA keys. Phase 1 shows interface, local-gw, remote-gw, identity settings, proposal and dhgrp. Select phase 2 entries by phase1name and compare proposal, pfs, dhgrp and selectors. The gateway list shows the selected name, peer addr, negotiated proposal and SA status.

No shared IKE proposal: set the agreed values at both peers

If the error began after an upgrade, compare the running values with the peer and the saved configuration. The release’s DH-default change matters only when the affected defaults were in use.

If debug identifies no shared IKE proposal and both peers support and have agreed on AES-256/SHA-256 with DH group 14, set those values on the existing phase 1 object at both ends:

Configuration change • conditional example; replaces the existing IKE proposal/group list
config vpn ipsec phase1-interface
    edit "<existing-tunnel>"
        set proposal aes256-sha256
        set dhgrp 14
    next
end

For a Child SA/PFS mismatch instead, edit the matching existing entry under config vpn ipsec phase2-interface: set the agreed proposal, and if PFS is required use set pfs enable with the agreed set dhgrp. Make the same agreement at the peer; do not change phase 1 to repair a phase 2-only mismatch. These changes can interrupt negotiation or rekey, so preserve the existing values first. Broadening every cipher and DH group can introduce weak options.

Configuration-address mismatch: fix the selected gateway or conflicting VIP

Compare the observed peer address, local interface/gateway and peer ID with the intended phase 1 object. Account for upstream NAT. Fortinet’s proposal-error example demonstrates a gateway mismatch, so this message is not exclusively a cipher mismatch.

If debug reports does not match configuration address, also check address ownership: an interface, VIP or IP pool can claim the peer address locally. A VIP for UDP 500/4500 may instead divert IKE away from the local VPN service. Address and VIP conflict cases.

With VDOMs disabled, run show system interface at the normal CLI prompt. With multiple VDOMs enabled, a global administrator first leaves the tunnel VDOM with next and end, then reads the interface inventory from the top-level prompt:

Read-only • global administrator; multi-VDOM interface inventory
config global
    show system interface
end

Return to the tunnel’s VDOM with config vdom and edit "<tunnel-vdom>", then read its VIPs and pools. Stay there for the remaining tunnel commands; use next and end when finished. A VDOM-restricted administrator runs the following commands in the assigned VDOM and asks a global administrator for the interface inventory if needed. With VDOMs disabled, run them at the normal prompt:

Read-only • tunnel’s VDOM, or single-VDOM normal prompt
show firewall vip
show firewall ippool

Check interface ip/secondary addresses, VIP extip/extintf and pool startip/endip against the observed peer address. For an IKE-port VIP, inspect portforward, protocol and extport. If the tunnel’s remote gateway is mistakenly a locally owned address, edit VPN → IPsec Tunnels → the tunnel → Network → IP Address to the actual reachable peer address.

If an unintended VIP captures UDP 500/4500, correct that specific VIP’s external address or port under Policy & Objects → Virtual IPs; first identify its referenced publishing policy so the change does not silently break a required service.

Compare the failed stage at both ends

AES-GCM combines encryption and integrity, but IKE still requires a PRF. Do not copy an IKE proposal into the ESP/PFS fields. The phase 1 and phase 2 settings describe different SAs.

Verify negotiation and the failing rekey

Check the selected transforms on both IKE and Child SAs, then test the protected flow. If the failure appears only at rekey, retain debug for that exchange rather than declaring success after the initial connection. Restore the previous tunnel-specific values if reverting, and stop the IKE debug.

References