Skip to main content
kinmun
New Member
April 13, 2015
Question

forticlient for iOS not working

  • April 13, 2015
  • 11 replies
  • 21030 views

we have users using IOS reported not able to access LAN and DMZ segment.

the same user tested his profile on a macbook and everything works fine.

what else is need to configure the forticlient for IOS ?

our firmware on the fortigate is 5.2.1

 

    11 replies

    Christopher_McMullan
    Staff
    Staff
    April 13, 2015

    How are FortiClient iOS devices connecting - SSLVPN web portal, or are they being restricted on-net or off-net?

    kinmun
    kinmunAuthor
    New Member
    April 13, 2015

    no restrictions.

    the user logging in has admin rights and have access to all the segments.

    he installed the forticlient for IOS on his phone. 

    should i asked him to try the web portal ??

    Christopher_McMullan
    Staff
    Staff
    April 13, 2015

    Just to be clear, I mean: where are iOS clients connecting from? Internal to your network? Externally using a VPN? Externally through a VIP?

    Where are the clients in terms of your network topology when their access attempts fail?

    kinmun
    kinmunAuthor
    New Member
    April 13, 2015

    connecting from external to LAN through the fortigate firewall.

    eg. telnet to network devices in the LAN failed after logging from the forticlient on the IOS phone.

    everything works if the user login using his macbook laptop with the same userid and password.

     

     

    Christopher_McMullan
    Staff
    Staff
    April 13, 2015

    How far do iOS clients get in the telnet process before it fails? Can you provide a screenshot?

    kinmun
    kinmunAuthor
    New Member
    April 14, 2015

    we are using sslvpn to login to office network from external. eg at home using normal  Internet line.

    seems like IOS user cannot only do web browsing but not others like telnet or ssh or RDP to servers.

    is sslvpn support in version 5.2.1 or 5.2.3 for IOS ?

    Christopher_McMullan
    Staff
    Staff
    April 14, 2015

    You can use Java-based applets and connection tools within the SSLVPN web portal to initiate non-HTTP traffic to internal resources, but unfortunately, the SSLVPN app itself (FortiClient) does not create a traditional tunnel. You would not be able to use Safari or a native telnet app on the iPhone to connect to resources.

    We're waiting on Apple for this.

    kinmun
    kinmunAuthor
    New Member
    April 15, 2015

    so no matter what method of VPN I used, it will get the same results ?

    i was thinking using IPSEC dialup client on the IOS to connect to the firewall

    Holy
    New Member
    April 15, 2015

    IPSes should work.

     

     

    kinmun wrote:

    so no matter what method of VPN I used, it will get the same results ?

    i was thinking using IPSEC dialup client on the IOS to connect to the firewall

    Christopher_McMullan
    Staff
    Staff
    April 15, 2015

    Yes, to clarify, it's only FortiClient which would not allow you to create a tunnel connection. You can use the built-in IPSec client in iOS to connect to a FortiGate appliance. In OS 5.2, the FortiGate can even do most of the work for you behind the scenes if you opt for the wizard.

    kinmun
    kinmunAuthor
    New Member
    April 21, 2015

    I m trying to setup the IPSec for IOS but there is always this error,

    is this normal?

     

    Christopher_McMullan
    Staff
    Staff
    April 21, 2015

    I can't see clearly from the summary lines why Phase 1 negotiations are failing.

     

    Can you provide diagnostic output, or screenshots showing the details from one of those log messages?

     

    diag debug reset

    diag debug enable

    diag debug application ike -1

    <attempt to connect to the VPN, then...>

    diag debug reset

    diag debug disable

    Simpalm
    New Member
    April 22, 2015

    kinmun wrote:

    we have users using IOS reported not able to access LAN and DMZ segment.

    the same user tested his profile on a macbook and everything works fine.

    what else is need to configure the forticlient for IOS ?

    our firmware on the fortigate is 5.2.1

     

    Thanks for sharing such a valuable post. I must say its quite informative. Keep posting such articles. www.simpalm.com