Skip to main content
kssupport
Visitor III
December 22, 2021
Question

help - forticlient Failed establish vpn connection - mismatch TLS VERSION

  • December 22, 2021
  • 1 reply
  • 8677 views

hi there,

 

need help. we use FORTIGATE 60D, with firmware 5.6.12

one of users suddenly fail to connect over vpn ssl.

error message: failed to establish the vpn connection. this may be caused by a mismatch in the tls version.

 

we've ticked all tls version in internet option.

user use windows 10 pro.

os build 19043.1348

 

this computer had no issue before. but somehow just got an issue now.

another computer use windows 10 has no problem at all for connect vpn ssl connection

 

anyone have experience same issue?

need help please.

thank you

 

1 reply

Markus_M
Staff & Editor
Staff & Editor
December 24, 2021

TLS version mismatch would indicate exactly that. TLS will be an encrypted tunnel over which the payload is transported.

The tunnel has to be build between two nodes and one will propose a set of ciphers according to its capabilities and it will conform the TLS version. If the server does not speak the same version, they cannot agree on a used cipher - that error is thrown. The Windows 10 device or the FortiClient could enforce certain TLS cipher suites that the FortiGate does not support.

 

Seeing the FortiGate Firmware version, you might consider upgrading it; the latest firmware for that FortiGate is 6.0.14.

To technically see what the client is sending, you can use wireshark on the client and filter for the FortiGate IP address and follow communication on the SSLVPN port you have configured.

That can be compared between both clients.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!