Skip to main content
pginete
Staff
Staff
October 9, 2025

Troubleshooting Tip: Dial-up IPsec VPN fails to connect with the error message 'Wrong Credentials EAP failed connecting'

  • October 9, 2025
  • 0 replies
  • 3206 views

Description

This article describes how to fix a dial-up IPsec VPN with FortiToken that fails to connect.

Scope

FortiGate, FortiAuthenticator.

Solution

The user cannot connect to a dial-up IPsec VPN with FortiToken and encountered the 'FortiClient Wrong Credentials EAP failed connecting' error.


8cda02d2.png


While successful when connecting without FortiToken. Another error that commonly appears is 'EAPPasswordError':

04.png


05.png


  1. RADIUS authentication:

The setup is a dial-up IPsec VPN IKEv2 using RADIUS authentication, where FortiGate is the RADIUS client while the FortiAuthenticator is the RADIUS server.

Enable ‘Allow OTP for EAP-MSCHAPv2 Authentication with FortiClient’ on the RADIUS Service policy of FortiGate on the FortiAuthenticator to fix these errors.

Allow OTP for EAP-MSCHAPv2 Authentication with FortiClient.png

 

MSCHAP2 is a prerequisite of this setup. 

Note: Similar error messages may also be observed when the user account is locked, the password is expired, or the authentication request is rejected by the external authentication server. If enabling this option does not resolve the issue, review FortiGate and authentication server debug logs to identify the exact cause of the rejection.


  1. SAML Authentication.

The setup is a dial-up IPsec VPN IKEv2 using SAML authentication, where FortiGate is the SAML Service Provider (SP).

Verify the 'set user-name' and 'set group-name' settings under 'config user saml' to ensure that the assertion statements match the attributes configured on the SAML Identity Provider (IdP).

config user saml
    edit <name>
        set user-name <value>
        set group <value>
end


Alternatively, verify Attribute Name and AttributeValue from the SAML debug output.

diagnose debug application samld -1
diagnose debug enable


In the line beginning with 'samlp:Response ID', check the Attribute Name and AttributeValue for user-name and group-name to confirm a match with the values configured on the FortiGate.

Related articles:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!