Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC pfsense and fortigate: could not decrypt payloads

    Scheduled Pinned Locked Moved IPsec
    2 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      GB13
      last edited by

      Hi,
      We're facing issue with VPN ipsec between pfsense and fortigate firewall. Tunnel randomly go down, on IPSEC log we see this:

      Sep 23 11:38:05	charon	4357	08[NET] <con100000|11101> sending packet: from X.X.X.X[500] to Y.Y.Y.Y[500] (76 bytes)
      Sep 23 11:38:05	charon	4357	08[ENC] <con100000|11101> generating INFORMATIONAL_V1 request 3006923544 [ HASH N(PLD_MAL) ]
      Sep 23 11:38:05	charon	4357	08[ENC] <con100000|11101> could not decrypt payloads
      Sep 23 11:38:05	charon	4357	08[ENC] <con100000|11101> invalid HASH_V1 payload length, decryption failed?
      Sep 23 11:38:05	charon	4357	08[NET] <con100000|11101> received packet: from Y.Y.Y.Y[500] to X.X.X.X[500] (428 bytes)
      
      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Your pre-shared key does not exactly match the key at the far side.

        https://docs.netgate.com/pfsense/en/latest/troubleshooting/ipsec.html#phase-1-pre-shared-key-mismatch

        If it works sometimes and not others, it may be that it only works when initiating in one direction. It could still be a problem with the key, but perhaps something more subtle like an extra space at the start/end that is ignored when checking on one side but not the other.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • T Thale referenced this topic on
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.