Skip to content

Site-to-site VPN troubleshooting: IKE phases, notify errors and SA status

For network administrators and MSP engineers who already support IPsec tunnels and know the basics of IKE, proposals, traffic selectors and NAT traversal (see Site-to-site VPN troubleshooting (IPsec)), and now need to read IKE negotiations message by message. You'll map log lines to IKEv1 phases and IKEv2 exchanges, interpret notify errors and retransmissions to find exactly where negotiation stops, read SA status (SPIs, ports, lifetimes, counters) in strongSwan and FortiGate output, diagnose problems that only appear after the tunnel is up, such as rekey failures from PFS mismatches and stale SAs, and compare both peers' settings to write a precise request to the other side's administrator. Grounded in RFC 7296, RFC 2409 and RFC 3948, the strongSwan documentation and Fortinet's IPsec diagnose reference. Work only on tunnels you're authorised to manage, and never send pre-shared keys or private keys by email or ticket. Ends with a supervisor-graded tunnel investigation.

Level
Advanced
Length
About 105 minutes
Contents
5 lessons · final exam
Status
Published · updated 10 Oct 2026

Skills you'll practise

  • Identify which IKE phase or exchange a log message belongs to (IKEv1 Main, Aggressive and Quick Mode; IKEv2 IKE_SA_INIT, IKE_AUTH, CREATE_CHILD_SA and INFORMATIONAL) and what it negotiates
  • Interpret IKE notify errors and retransmissions to locate where a negotiation fails
  • Read SA status output to check SPIs, ports, NAT traversal, lifetimes and traffic counters
  • Diagnose problems that appear after the tunnel is up: rekey failures, lifetime expiry, stale SAs and one-way traffic
  • Compare both peers' settings and write an evidence-based request to the remote peer's administrator

Course outline

  1. 1.Identify which IKE phase or exchange a log message belongs to and what it negotiatesLesson · 18 min
  2. 2.Interpret IKE notify errors and retransmissions to locate where negotiation failsLesson · 18 min
  3. 3.Read SA status output: SPIs, ports, NAT traversal, lifetimes and countersLesson · 16 min
  4. 4.Diagnose problems that appear after the tunnel is up: rekeys, lifetimes, stale SAs and one-way trafficLesson · 16 min
  5. 5.Compare both peers' settings and write an evidence-based request to the remote administratorLesson · 15 min
  6. 6.Site-to-site VPN troubleshooting: IKE phases, notify errors and SA status: knowledge checkKnowledge check · 14 questions
  7. 7.Site-to-site VPN troubleshooting: IKE phases, notify errors and SA status: practical exerciseKnowledge check · 1 question
  8. 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.