Skip to main content
jiahoong112
Staff
Staff
May 22, 2025

Troubleshooting Tip: Users connecting from CGNAT network are unable to connect to FortiSASE

  • May 22, 2025
  • 0 replies
  • 715 views
Description

This article describes what to do when client devices behind a CGNAT network fail to connect to FortiSASE VPN.

Scope FortiSASE.
Solution

Follow the steps in the following KB article to perform a capture using Fortinet Support Tool on FortiSASE: Technical Tip: How to perform an SSL VPN debug on a specific Point of Presence (PoP) in FortiSASE.

 

Opening the capture taken with the Fortinet Support Tool:

 

jiahoong112_0-1747896233401.png

 

The 'source IP check failed' error message can be seen as highlighted.

A change will have to be made on the FortiSASE backend to resolve the issue, and only the FortiSASE ops team is able to do this. Open a TAC ticket.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!