Skip to main content
fabs
Visitor III
September 25, 2023
Question

cannot longer connect FortiClientVPN 7.2.2.0116 Azure SAML MFA

  • September 25, 2023
  • 31 replies
  • 44406 views

Hello,

 

since updating iPhone iOS from the last version 16 to the current 17.0.1, connecting via FortiClientVPN is no longer possible. The Azure SAML authentication takes place, but it stops at "Connection".
FortiClient VPN 7.2.2.0116
Fortigate 7.2.5 build1517
Can anyone here report the same problem?

31 replies

fabs
fabsAuthor
Visitor III
September 25, 2023

Hi all,

I must revise the first statement. It does not work even with iOS 16.
This has been the case since Friday. With Windows 10 and Android the connection works.
Is there a way to log the iOS connections?

Oak6t
Explorer
September 25, 2023

I am having the same issue. It is specific to the FortinetClient version 7.2.2.0116.

fabs
fabsAuthor
Visitor III
September 25, 2023

Hi
yes it looks like an issue with 7.2.2.0116

2023-09-25 13:47:56 [299:root:24]allocSSLConn:310 sconn 0x7f7de3de00 (0:root) 2023-09-25 13:47:56 [299:root:24]DTLS established: DTLSv1 ECDHE-RSA-AES256-GCM-SHA384 from 109.43.179.41 2023-09-25 13:47:57 [301:root:21]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [301:root:21]sslConnGotoNextState:311 error (last state: 1, closeOp: 0) 2023-09-25 13:47:57 [301:root:21]Destroy sconn 0x7f7d1c2800, connSize=0. (root) 2023-09-25 13:47:57 [301:root:21]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [300:root:22]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [300:root:22]sslConnGotoNextState:311 error (last state: 1, closeOp: 0) 2023-09-25 13:47:57 [300:root:22]Destroy sconn 0x7f7d154000, connSize=0. (root) 2023-09-25 13:47:57 [300:root:22]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [302:root:21]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [302:root:21]sslConnGotoNextState:311 error (last state: 1, closeOp: 0) 2023-09-25 13:47:57 [302:root:21]Destroy sconn 0x7f7d154000, connSize=0. (root) 2023-09-25 13:47:57 [302:root:21]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [296:root:20]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [296:root:20]sslConnGotoNextState:311 error (last state: 1, closeOp: 0) 2023-09-25 13:47:57 [296:root:20]Destroy sconn 0x7f7d15a000, connSize=0. (root) 2023-09-25 13:47:57 [296:root:20]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [297:root:21]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:47:57 [297:root:21]sslConnGotoNextState:311 error (last state: 1, closeOp: 0) 2023-09-25 13:47:57 [297:root:21]Destroy sconn 0x7f7d139800, connSize=0. (root) 2023-09-25 13:47:57 [297:root:21]SSL state:warning close notify (109.43.179.41) 2023-09-25 13:48:02 [208] __fnbamd_remote_ca_refresh- 2023-09-25 13:48:10 [299:root:24]sslvpn_dtls_timeout_check:312 waiting for client hello timeout. 2023-09-25 13:48:10 [299:root:24]Destroy sconn 0x7f7de3de00, connSize=0. (root) 2023-09-25 13:48:25 [299:root:25]allocSSLConn:310 sconn 0x7f7de3de00 (0:root)
tristan1337
Visitor III
September 26, 2023

Same, doesn't work anymore since Version 7.2.2.0116

ShayneA
New Member
September 26, 2023

Same. Fortinet please fix the issue.

Oak6t
Explorer
September 26, 2023

Can someone from Fortinet address the issue with their latest FortiClient VPN app?

hbac
Staff
Staff
September 26, 2023

Hi @fabs,

 

Are you using FortiToken for MFA? Does it work without MFA enabled? You can try to reinstall FortiClient and FortiToken app on the iOS device. 

 

Regards, 

fabs
fabsAuthor
Visitor III
September 27, 2023

Hi @hbac 
We using FortiClientVPN 7.2.2.0116 with SAML SSO MFA, no Forti Token.
Reinstall of FortiClientVPN not resolved the issue.
The Authentication is working but not the SSL handshake.

When we use FortiClient 7.2.2.0116 its working.

sslee6630
Visitor III
October 6, 2023

Thanks

appstore - FortiClientVPN 7.2.2.0116 => not working (Connecting...)

appstore - FortiClient 7.2.2.0116 => working

jcordero
Visitor III
September 26, 2023

I have same issue since I updated to IOS 17.0.1. 
Fortigate: v7.2.5 build1517  
Fortivpnclient version: 7.2.2.0116
MFA: SAML - SSO 

jcordero
Visitor III
September 26, 2023

Here some findings:  
The app FortiClient VPN (https://apps.apple.com/us/app/forticlient-vpn/id1475674905) doesn't work after IOS upgrade.

But I installed FortiClient (without VPN) (https://apps.apple.com/us/app/forticlient/id1474294106) and the connection was successful.
Same app version:  7.2.2.0116


 

ShayneA
New Member
September 26, 2023

I have tested with FortiClient (without VPN) and was able to connect as well.

PBalochini
Explorer II
September 27, 2023

Hello,

 

Same problems with all iphones using version 7.2.2.0116. Thats the problem.

I install FORTINET VPN Client on my older IPHONE X and is comes with version 7.2.1.0110 and are working as expected.


There are no way do downgrade in APPLESTORE.

The FORTINET VPN CLIENT version 7.2.2 was updated 4 days later. ( 7.2.2.0116)
SSLVPN idle-timeout not disconnnection FCT IOS
SSLVPN DTLS iomplementation
UPDADE to OpenSSL 3.1.2
SSLVPN bug fixes

Sure some thing above will cause this mal funcion....

PBalochini
Explorer II
September 27, 2023

Turn ON debug and got the error 

2023-09-27 06:23:42 [272:root:1310]epollFdHandler,560, sconn=0x7f75c54800[9,-1,-1,-1,-1], fd=9, event=25.
2023-09-27 06:23:42 [272:root:1310]epollFdHandler:630 s: 0x7f75c54800 event: 0x19
2023-09-27 06:23:42 [272:root:1310]Destroy sconn 0x7f75c54800, connSize=0. (root)



Expected was
2023-09-27 06:28:13 [274:root:1311]req: /remote/saml/login
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.microsoft.com/identity/claims/tenantid
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.microsoft.com/identity/claims/objectidentifier
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.microsoft.com/identity/claims/displayname
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.microsoft.com/identity/claims/identityprovider
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.microsoft.com/claims/authnmethodsreferences
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.microsoft.com/claims/authnmethodsreferences
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.microsoft.com/ws/2008/06/identity/claims/wids
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.microsoft.com/ws/2008/06/identity/claims/wids
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
2023-09-27 06:28:13 [274:root:1311]stmt: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
2023-09-27 06:28:13 [274:root:1311]stmt: username
pmeet
Staff
Staff
September 27, 2023

Hello all,

 

It's a same issue with simple VPN as well, just tested this with my lab setup

MP-AGF
Explorer
October 2, 2023

Same Problem. The "big" FortiClient is temporary workaround.