Site-to-site VPN troubleshooting: IKE phases, notify errors and SA status
For network administrators and MSP engineers who already support IPsec tunnels and know the basics of IKE, proposals, traffic selectors and NAT traversal (see Site-to-site VPN troubleshooting (IPsec)), and now need to read IKE negotiations message by message. You'll map log lines to IKEv1 phases and IKEv2 exchanges, interpret notify errors and retransmissions to find exactly where negotiation stops, read SA status (SPIs, ports, lifetimes, counters) in strongSwan and FortiGate output, diagnose problems that only appear after the tunnel is up, such as rekey failures from PFS mismatches and stale SAs, and compare both peers' settings to write a precise request to the other side's administrator. Grounded in RFC 7296, RFC 2409 and RFC 3948, the strongSwan documentation and Fortinet's IPsec diagnose reference. Work only on tunnels you're authorised to manage, and never send pre-shared keys or private keys by email or ticket. Ends with a supervisor-graded tunnel investigation.
- Level
- Advanced
- Length
- About 105 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify which IKE phase or exchange a log message belongs to (IKEv1 Main, Aggressive and Quick Mode; IKEv2 IKE_SA_INIT, IKE_AUTH, CREATE_CHILD_SA and INFORMATIONAL) and what it negotiates
- Interpret IKE notify errors and retransmissions to locate where a negotiation fails
- Read SA status output to check SPIs, ports, NAT traversal, lifetimes and traffic counters
- Diagnose problems that appear after the tunnel is up: rekey failures, lifetime expiry, stale SAs and one-way traffic
- Compare both peers' settings and write an evidence-based request to the remote peer's administrator
Course outline
- 1.Identify which IKE phase or exchange a log message belongs to and what it negotiatesLesson · 18 min
- 2.Interpret IKE notify errors and retransmissions to locate where negotiation failsLesson · 18 min
- 3.Read SA status output: SPIs, ports, NAT traversal, lifetimes and countersLesson · 16 min
- 4.Diagnose problems that appear after the tunnel is up: rekeys, lifetimes, stale SAs and one-way trafficLesson · 16 min
- 5.Compare both peers' settings and write an evidence-based request to the remote administratorLesson · 15 min
- 6.Site-to-site VPN troubleshooting: IKE phases, notify errors and SA status: knowledge checkKnowledge check · 14 questions
- 7.Site-to-site VPN troubleshooting: IKE phases, notify errors and SA status: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- RFC 7296: Internet Key Exchange Protocol Version 2 (IKEv2) (exchanges, notify error types, traffic selector narrowing, liveness checks, ports)
- RFC 2409: The Internet Key Exchange (IKE) (IKEv1 phase 1 Main and Aggressive Mode, phase 2 Quick Mode)
- RFC 3948: UDP Encapsulation of IPsec ESP Packets (port 4500, non-ESP marker, NAT keepalives)
- strongSwan documentation: Introduction to the IPsec Protocol (ESP, SPIs, IKEv2 exchanges)
- strongSwan documentation: NAT Traversal (NAT detection, port 4500, keepalives)
- strongSwan documentation: Logging (log levels and subsystems)
- strongSwan documentation: swanctl --list-sas
- strongSwan documentation: swanctl.conf reference (proposals, esp_proposals, traffic selectors, rekey and lifetimes, DPD, start_action)
- strongSwan documentation: FAQ (IKE_AUTH retransmits with certificates, fragmentation)
- Fortinet FortiOS 7.6 Administration Guide: IPsec related diagnose commands
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.