During Phase 2, OPNsense sends a valid QUICK_MODE request:
but the FortiGate never responds with a QUICK_MODE reply, NO_PROPOSAL_CHOSEN, or INVALID_ID_INFORMATION.
Instead, it only sends DPD packets and a vendor-specific notify (24576), while OPNsense retransmits the QUICK_MODE request until timeout.
The latest logs suggest that:
Code Select
generating QUICK_MODE request [ HASH SA No KE ID ID ]but the FortiGate never responds with a QUICK_MODE reply, NO_PROPOSAL_CHOSEN, or INVALID_ID_INFORMATION.
Instead, it only sends DPD packets and a vendor-specific notify (24576), while OPNsense retransmits the QUICK_MODE request until timeout.
The latest logs suggest that:
- Phase 1 is fully functional
- Connectivity between peers is fine
- The failure occurs only during Phase 2 negotiation
"