OPNsense Forum

English Forums => 26.7 Series => Topic started by: oegeeks on August 28, 2026, 12:38:22 PM

Title: PFS in a ip-sec tunnel with a fortigate
Post by: oegeeks on August 28, 2026, 12:38:22 PM
I can not get pfs to work in the tunnel.
Right now the tunnel is working, but without pfs.

As i understood, in the child section, in the phase 2 esp section there has to be choosen the same df group as on the fortigate.
The groups are the same, as the encryption type: aes128-sha256 (dh 14).

But the error always is : 06[IKE1] <ce786d32-7e3b-435e-aa63-c7121b0c2664|1961> received NO_PROPOSAL_CHOSEN error notify
Any hints how to get this to work?

Title: Re: PFS in a ip-sec tunnel with a fortigate
Post by: tuto2 on August 28, 2026, 03:09:07 PM
Make sure the proposals are actually the same for IKE (the connection or phase 1). Seems like it fails there instead of your phase 2, which use a separate set of proposals.