IPSEC pfsense and fortigate: could not decrypt payloads
-
Hi,
We're facing issue with VPN ipsec between pfsense and fortigate firewall. Tunnel randomly go down, on IPSEC log we see this:Sep 23 11:38:05 charon 4357 08[NET] <con100000|11101> sending packet: from X.X.X.X[500] to Y.Y.Y.Y[500] (76 bytes) Sep 23 11:38:05 charon 4357 08[ENC] <con100000|11101> generating INFORMATIONAL_V1 request 3006923544 [ HASH N(PLD_MAL) ] Sep 23 11:38:05 charon 4357 08[ENC] <con100000|11101> could not decrypt payloads Sep 23 11:38:05 charon 4357 08[ENC] <con100000|11101> invalid HASH_V1 payload length, decryption failed? Sep 23 11:38:05 charon 4357 08[NET] <con100000|11101> received packet: from Y.Y.Y.Y[500] to X.X.X.X[500] (428 bytes)
-
Your pre-shared key does not exactly match the key at the far side.
If it works sometimes and not others, it may be that it only works when initiating in one direction. It could still be a problem with the key, but perhaps something more subtle like an extra space at the start/end that is ignored when checking on one side but not the other.
-
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.