Skip to main content
daffoml
New Member
August 17, 2026
Question

IPSEC RA troubleshooting

  • August 17, 2026
  • 4 replies
  • 115 views

have a FG 70G 7.4.12 and a windows client with free VPN 7.4.3.4726

I have followed the doc:

https://docs.fortinet.com/document/fortigate/7.4.12/administration-guide/785501

 

but when I try to connect, the client says “Timeout while connecting”

 

I have diagnose sniffer packet wan1 "udp and port 500" running, and see 4 packets every time I try to connect like:

19.844532 1.247.132.25.1012 -> 214.153.140.239.500: udp 668

The odd part (to me) is that I do not see anything in the GUI System Events > VPN Logs >Memory.

I’ve made sure the proposals match on both sides.

I’ve done this before multiple times on 7.2 and older, and never had these kinds of problems.

Any suggestions?

4 replies

sjoshi
Staff
Staff
August 17, 2026

timeout means it could be issue with network connectivity.

is this the user public IP 1.247.132.25?

further run ike debug on the fortigate

Thanks, Salon
daffoml
daffomlAuthor
New Member
August 18, 2026

Thank you for the reply.

that is not the real public IP, I changed it for the post, but in the logs it is correct.

 

With the IKE debug on, I did see what the problem is, but not sure how to fix it.  I have two IPSEC RA tunnels, one for internal employees and one for vendors, I have the vendor pre-share in the client, but it was choosing the internal SA proposal.

Just to get this sped along, I deleted the internal, as it’s not in use a this time, but now I get “no SA proposal chosen”  when trying to connect.

I have changed the Pre-shared key and made sure it matched.  I also went through all the phase 1 settings and made sure they were identical.

funkylicious
SuperUser
SuperUser
August 19, 2026

when you have multiple IPsec tunnel terminating on the same WAN interface, its best that you use peer id ( for IKEv1 ) and localid ( in FortiClient ) or network-id ( for IKEv2 ) and in FCT ( this )

 

 

"jack of all trades, master of none"
New Member
August 19, 2026

I ran into a very similar issue with our contractors using that version of the free client as well. With the sniffer I could see traffic for SAML and then once SAML was finished, nothing. Also no logs or anything to indicate they had ever connected. 

I had a ticket with TAC thinking I botched the IPSec config on the FortiGate,but turns out the issue seems to be the client. I was able to use the support portal > Downloads > firmware > Forticlient to get a 7.4.2 version of the free client. That connected successfully and I’m now waiting to hear back from our contractors to confirm this works for them too. 

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!