• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSEC pfsense and fortigate: could not decrypt payloads

Scheduled Pinned Locked Moved IPsec
2 Posts 2 Posters 1.1k Views 2 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G Offline
    GB13
    last edited by Sep 23, 2021, 10:06 AM

    Hi,
    We're facing issue with VPN ipsec between pfsense and fortigate firewall. Tunnel randomly go down, on IPSEC log we see this:

    Sep 23 11:38:05	charon	4357	08[NET] <con100000|11101> sending packet: from X.X.X.X[500] to Y.Y.Y.Y[500] (76 bytes)
    Sep 23 11:38:05	charon	4357	08[ENC] <con100000|11101> generating INFORMATIONAL_V1 request 3006923544 [ HASH N(PLD_MAL) ]
    Sep 23 11:38:05	charon	4357	08[ENC] <con100000|11101> could not decrypt payloads
    Sep 23 11:38:05	charon	4357	08[ENC] <con100000|11101> invalid HASH_V1 payload length, decryption failed?
    Sep 23 11:38:05	charon	4357	08[NET] <con100000|11101> received packet: from Y.Y.Y.Y[500] to X.X.X.X[500] (428 bytes)
    
    1 Reply Last reply Reply Quote 0
    • J Offline
      jimp Rebel Alliance Developer Netgate
      last edited by Sep 23, 2021, 12:18 PM

      Your pre-shared key does not exactly match the key at the far side.

      https://docs.netgate.com/pfsense/en/latest/troubleshooting/ipsec.html#phase-1-pre-shared-key-mismatch

      If it works sometimes and not others, it may be that it only works when initiating in one direction. It could still be a problem with the key, but perhaps something more subtle like an extra space at the start/end that is ignored when checking on one side but not the other.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • T Thale referenced this topic on Aug 3, 2022, 1:19 PM
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received