Troubleshooting Tip: VPN with Smart Card PKI authentication, FortiClient VPN progress failed at 40% and would not ask for PIN code
| Description | This article describes how to troubleshoot an issue whereby, while attempting a VPN connection with Smart Card PKI authentication, the FortiClient VPN progress failed at 40% and would not ask for the PIN code to proceed with the connection. |
| Scope | FortiClient v7.2, and v7.4. |
| Solution | VPN setup:
Note: In some cases, additional settings on FortiGate may be required, depending on the article Technical Tip: Upgrade to the latest MS Windows 10 version breaks the SSLVPN login using PKI with some crypto cards:
config vpn ssl settings
In a successful VPN scenario:
In a failure VPN scenario:
When facing the above issue, follow the guidelines below to troubleshoot (applicable to both FortiClient VPN-only version and FortiClient full-version):
If the FortiClient is managed by EMS, manually add the parameter <async_mode>1</asycn_mode> in the endpoint profile.
After verifying all 3 steps above, the issue should be resolved.
Further reading about async_mode: Asynchronous Operation. |







