Hello ,
I'm trying to setup IPSec S2S VPN Tunnel to non-Meraki peer . The only thing which I found in Event Log is
Non-Meraki VPN negotiation
msg: FIPS mode disabled
I tried to find solution but no success , could you advice me what I can do ?
Best regards,
Czarek
AI-generated summary
From your community moderators: We're experimenting with using AI to summarize some of our longer threads. The summary has been reviewed by humans for accuracy.
Problem
The original poster encountered a "FIPS mode disabled" message during Non-Meraki VPN negotiation, indicating their MX device was behind NAT and experiencing VPN connectivity issues with a third-party device.
Summary
The discussion revealed that the problem stemmed from incompatible IPsec encryption policies between the Meraki device and the non-Meraki endpoint. The solution involved researching Meraki's FIPS documentation and adjusting the IPsec Phase 1 and Phase 2 configurations to use weaker but compatible encryption algorithms, specifically switching to 3DES and MD5 instead of stronger modern ciphers. One community member confirmed this approach worked for their setup, though they expressed reluctance about using the less secure 3DES and MD5 algorithms. The thread suggests that resolving FIPS mode disabled errors typically requires experimenting with different Phase 1 and Phase 2 configurations until finding a compatible combination between the Meraki and non-Meraki devices.
... View more