I tried without PFS and the result is the same. I don't have access to the remote firewall but as I remember, it is supposed to accept both proposals on DHGroup 5 and DHGroup 14. Here is the full log output : 2017-08-24 15:52:58.828 +0200 [PNTF]: { 3: 12}: ====> PHASE-2 NEGOTIATION STARTED AS INITIATOR, (QUICK MODE) <==== ====> Initiated SA: WAN_IP[500]-DST_WAN_IP[500] message id:0x8C47EF4D <==== 2017-08-24 15:52:58.845 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4). 2017-08-24 15:53:01.015 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4). 2017-08-24 15:53:04.005 +0200 [PNTF]: { 3: }: notification message 36137:R-U-THERE-ACK, doi=1 proto_id=1 spi=596ffb652fb039fd 8ebc5e12d094fa99 (size=16). 2017-08-24 15:53:04.005 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4). 2017-08-24 15:53:05.884 +0200 [PERR]: packet (5) shorter than isakmp header size. 2017-08-24 15:53:09.005 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4). 2017-08-24 15:53:15.884 +0200 [PERR]: packet (5) shorter than isakmp header size. 2017-08-24 15:53:17.015 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4). 2017-08-24 15:53:25.884 +0200 [PERR]: packet (5) shorter than isakmp header size. 2017-08-24 15:53:29.002 +0200 [PNTF]: { : 12}: ====> PHASE-2 NEGOTIATION FAILED AS INITIATOR, (QUICK MODE) <==== ====> Failed SA: WAN_IP[500]-DST_WAN_IP[500] message id:0x8C47EF4D <==== Due to negotiation timeout. 2017-08-24 15:53:34.015 +0200 [PNTF]: { 3: }: notification message 36137:R-U-THERE-ACK, doi=1 proto_id=1 spi=596ffb652fb039fd 8ebc5e12d094fa99 (size=16).
... View more