IPSEC VPN Connection with Forticlient EMS fails
Hello everybody,
we are currently using a Fortigate and ForticlientOnlyVPN with an IPSEC XAUTH configuration.
Since we are now moving to Forticlient EMS (up to date server and client) and after testing Forticlient 7.4.0.1658 the following problem occurs:
If I manually add the IPSEC connection we are using with the OnlyVPN to the new Client (managed with EMS), succesful connection is possible.
If I config the same IPSEC parameters on EMS and distribute it, remote access does not work.
The error message on the client states something with Error: Aggressive Mode and the log files hints a certificate error (I replaced some sensitive information):
21.08.2024 08:12:21 error ipsecvpn date=2024-08-21 time=08:12:20 logver=1 id=96567 type=securityevent subtype=ipsecvpn eventtype=error level=error uid=664559DDC9CC478DBC0D3A5B686BAA87 devid=FCT8002127206410 hostname=PC pcdomain=domain deviceip=IP devicemac=MAC site=default fctver=7.4.0.1658 fgtserial=N/A emsserial=FCTEMS8824006969 os="Microsoft Windows 11 Professional Edition, 64-bit (build 22631)" user=USER msg="loc_ip=locIP loc_port=500 rem_ip=remIP rem_port=500 out_if=0 vpn_tunnel=Tunnel status=negotiate_error init=local mode=xauth_clinet stage=1 dir=inbound status=failureInitiator: parsed remIP aggressive mode message #1 (ERROR)" vpntunnel=Tunnel 21.08.2024 08:12:21 info ipsecvpn date=2024-08-21 time=08:12:20 logver=1 id=96577 type=securityevent subtype=ipsecvpn eventtype=error level=info uid=664559DDC9CC478DBC0D3A5B686BAA87 devid=FCT8002127206410 hostname=PC pcdomain=Domain deviceip=IP devicemac=MAC site=default fctver=7.4.0.1658 fgtserial=N/A emsserial=FCTEMS8824006969 os="Microsoft Windows 11 Professional Edition, 64-bit (build 22631)" user=User msg="IKE phase1 authentication fail as peer's certificate is not verified" vpntunnel=Tunnel locip=locIP locport=500 remip=remIP remport=500I also tried to "blindly" import the XML of the manually configured IPSEC into EMS which also does not work.
Any ideas where the problem can reside? I already opened a ticket but no luck so far.
Kind regards,
