FortiClient VPN: Intermittent DNS & Ping Failures Despite Policy & Traffic Looking Fine
I'm facing an intermittent issue with FortiClient SSL-VPN where connection doesn't work properly, even though everything appears correctly configured. I’ve tested several FortiClient versions, but the issue persists randomly.
Issue Summary:
FortiClient connects successfully.
VPN routes are installed correctly.
Traffic (DNS + ICMP) is visible on the FortiGate.
Wireshark on the client confirms replies (ICMP + DNS) are reaching the VPN adapter.
Despite this, ping and nslookup hang or fail. And every other traffic...
This issue happens roughly 1 out of every 10 VPN connections — seemingly at random.
Tested FortiClient Versions:
7.4.3
7.0.9
7.0.6
Issue appears intermittently across all versions.
What I've Checked:
FortiGate policies are identical for all users.
Split tunneling behavior is consistent.
DNS server (10.0.0.11) replies are seen in Wireshark but not accepted by the OS.
Disabling Windows Firewall and antivirus doesn't consistently solve the issue.
MTU tests with ping -f -l show no consistent fragmentation problems.
Has anyone seen this?
Any known FortiClient or Windows behavior that could cause this?
Thanks in advance!
