Skip to main content
GWFortinet
Staff
Staff
July 28, 2025

Technical Tip: SSL VPN connection failed for end-user behind CGNAT

  • July 28, 2025
  • 0 replies
  • 2851 views

Description

This article describes why an end-user behind CGNAT cannot connect to SSL VPN.

Scope

FortiGate, SSL VPN.

Solution

Along with IPv4 address exhaustion, the technology called CGNAT is being used widely by ISPs (such as NBN providers in Australia). CGNAT allows multiple end users to share a single public IPv4 address (pool).


If the ISP does not apply CGNAT persistence (aka sticky IP), the end user traffic appears to come from a shared public IP address (pool) when interacting with the Internet. This can be verified through a third-party website (e.g., WhatIsMyIPAddress.com), and a few different public IP addresses can be observed while refreshing the page multiple times.


This behavior brings up a challenge for the end user connecting to SSL-VPN, especially for the FortiGate firmware upgraded to v7.2.11, v7.4.8, and v7.6.1 onwards.

 

Note: Starting in FortiOS v7.6.3, the SSL VPN tunnel mode feature is replaced with IPsec VPN.

 

Since the public IP changes frequently, when the client initiates the SSL VPN connection, multiple public IP addresses are tried to connect to the SSL VPN gateway, which triggers the 'source IP check failed'.


To mitigate the issue, the following command is required:

 

config vpn ssl settings
  set auth-session-check-source-ip disable
end

 

Disabling the setting reduces security. Alternatively, call the ISP to opt out of CGNAT.

 

Note:

If calling the ISP to opt out of CGNAT is not an option.

 

These are recommended measures to add layers of security:

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.