Fortigate 8.0.0 Remote VPN Using Cert + EAP
I’ve been straining my brain for weeks on this. It seems like it should be so simple. Is anyone aware of any bugs with Remote IPSEC VPN and 8.0? I have followed this documentation but i’m obviously missing something. I’m attempting to use the Forticlient cert (i was doing my internal pki, but found to check EMS tags i needed to present the EMS cert) and i keep getting hung up here:
[1742] fnbamd_auth_session_done-Session done, id=84988985766011
[1209] __fnbamd_cert_auth_run-Exit, req_id=84988985766011
[1785] create_auth_cert_session-fnbamd_cert_auth_init returns 0, id=84988985766011
[1698] auth_cert_success-id=84988985766011
[1321] fnbamd_cert_auth_copy_cert_status-req_id=84988985766011
[1329] fnbamd_cert_auth_copy_cert_status-Matched peer user 'Remote-Employee_peer'
[1458] fnbamd_cert_auth_copy_cert_status-Cert st 210, req_id=84988985766011
[356] fnbamd_comm_send_result-Sending result 0 (nid 672) for req 84988985766011, len=2776
[360] fnbamd_comm_send_result-Failed send reply (2788, errno 101)
[1567] destroy_auth_cert_session-id=84988985766011
[2047] handle_child_rsp-Auth rsp 84988985766011, session not created, line 76
[1293] fnbamd_cert_auth_uninit-req_id=84988985766011
[1996] fnbamd_ldaps_destroy-
[1667] fnbamd_rads_destroy-
All the cert checks and EMS checks above are fine, but it fails here every time. Wondering if someone here can help
