Troubleshooting Tip: Users connecting from CGNAT network are unable to connect to FortiSASE
| Description | This article describes what to do when client devices behind a CGNAT network fail to connect to FortiSASE VPN. |
| Scope | FortiSASE. |
| Solution | Follow the steps in the following KB article to perform a capture using Fortinet Support Tool on FortiSASE: Technical Tip: How to perform an SSL VPN debug on a specific Point of Presence (PoP) in FortiSASE.
Opening the capture taken with the Fortinet Support Tool:
The 'source IP check failed' error message can be seen as highlighted. A change will have to be made on the FortiSASE backend to resolve the issue, and only the FortiSASE ops team is able to do this. Open a TAC ticket. |

