Skip to main content
jie
Staff
Staff
November 3, 2025

Troubleshooting Tip: FortiClient IPSEC VPN connection issue due to the Windows IKEEXT is using port 4500

  • November 3, 2025
  • 0 replies
  • 3320 views
Description This article describes how to troubleshoot and fix an IPSec VPN connection issue, which is caused by the Windows svchost.exe - IKEEXT service occupying port 4500.
Scope FortiClient.
Solution

FortiClient stuck at connecting status, when checking the ports 500 and 4500, notice it is being used by svchost.exe IKEEXT service as shown below:

 

1.PNG

 

The most effective and common solution is to disable the Windows IPSec service, which frees up the ports for the VPN client, and turn it back on later if needed.

 

  1. Open the Run dialog by pressing Win + R.
  2. Type services.msc and press Enter. This opens the Services management console.
  3. In the list of services, find IPSec Policy Agent. On newer versions of Windows 10/11, it might be called: IKE and AuthIP IPsec Keying Modules.
  4. Double-click on the service to open its properties.
  5. Select the Stop button to stop the service immediately.
  6. In the Startup type dropdown menu, change it to Disabled. This prevents it from starting automatically on the next boot and causing the conflict again.

 

1.PNG

 

1.PNG

 

  1. Select Apply and then OK.
  2. Try to connect VPN again.

 

Note:

Changing the default IPsec port on both FortiClient and FortiGate can be another workaround for this issue.