Skip to main content
mmjo
New Member
November 8, 2024
Question

Forticlient ems ipsec problems

  • November 8, 2024
  • 1 reply
  • 998 views

Hi.

i'm doing a poc on forticlient ems for the purpos on using it as remote ipsec vpn and ztna.

I'm having problems with the vpn part.

right now iv don't the vpn before login (auto part) with the machine certificate and that works fine and when i log in the user certificate takes over, that's fine and working.

 

But when i close the lid on my laptop the computer lock, and when i come back and open it again it's lock and the vpn before login starts and when i use my windows hello and log me in it's stuck with the machine certificate and the user dont takes over.

Anyone of you having solved that?

 

Morten

1 reply

HarshChavda
Staff
Staff
November 9, 2024

Hello @mmjo ,

 

Can you check Forticlient EMS certificate switching settings which ensure the certificate switch setting is correctly configured to switch from the machine certificate to the user certificate after login. Also can you check idle timeout settings.

mmjo
mmjoAuthor
New Member
November 11, 2024

Hi.

The cert switching is that the autoconnect_tunnel?

Got the Mach tunnel as on_os_start_connect and the user tunnel as autoconnect_tunnel and the on_os_start_connect_has_prio = 0

Is it each tunnel timeout you want?