Skip to main content
vanhema
New Member
July 28, 2026
Question

IPSEC VPN from Android using certificate

  • July 28, 2026
  • 3 replies
  • 153 views

Hi,

FortiClient VPN on Android 16 disconnects immediately after a successful IKEv2 certificate authentication against a FortiGate 101F running FortiOS 7.4.12.

FortiGate debug shows:

certificate validation succeeded
signature verification succeeded
authentication succeeded
mode-cfg assigned IPv4 address 10.242.221.100
added IPsec SA
tunnel up event assigned address 10.242.221.100

 

Immediately after that, the Android client sends:
received informational request
processing delete request (proto 1)
deleting IKE SA

FortiClient Android only shows:
START → STARTED → TUNNELLING → ERROR → DISCONNECTED

 

No useful error is displayed. Logs show:
authenticationFailure false
connectionFailure false
failureReason null

 

The same VPN configuration works perfectly from Windows.
DNS changes, send-cert-chain disable, and fragmentation changes did not change the behaviour.

 

The FortiGate uses a wildcard server certificate. Client certificate authentication is successful.


Has anyone seen Android 16 / FortiClient Android immediately delete the IKE SA after successful certificate auth? 
Unable to configure it on iPhone too... Doesn't see the certificate in the store.

 

Thank you in advance for your help because it’s mandatory to migrate to 7.6 too.

3 replies

HarryTran
Staff
Staff
July 28, 2026

Hi ​@vanhema 

May I know:
• What exact FCT Android version? Was it upgrade or fresh installed ?
• Is the client certificate self-signed (OpenSSL-generated) or issued by a CA (MS AD CA, internal CA, public CA)?

 

vanhema
vanhemaAuthor
New Member
July 29, 2026

Hello ​@HarryTran ,

I tested this on several smartphones (Samsung S25, Samsung S26, iPhone, and Google Pixel) and the issue occurs on all of them. (FCT version 7.4.6.0218 - fresh installed)

The user certificate is issued by our internal CA. I imported both the CA certificate and the PKCS#12 (.p12) certificate on each device.

For reference, the VPN connection works without any issue on a Windows PC using the same certificate and configuration.

 

Have a nice day

HarryTran
Staff
Staff
August 5, 2026

Hi ​@vanhema,

What you described is very close to a known issue where FortiGate does not send the intermediate CA certificate during IKEv2 certificate authentication. Windows may still work because it already has the intermediate CA, while the mobile device cannot validate the FortiGate certificate and disconnects.

Could you please perform this simple test?

  1. Check whether an intermediate CA is used

  • On FortiGate, go to System → Certificates and open the wildcard/server certificate used by the IPsec tunnel.

  • Note the certificate’s Issuer.

  • On the working Windows PC, run certmgr.msc and open Intermediate Certification Authorities → Certificates.

  • Look for a CA certificate whose Subject matches the Issuer of the FortiGate server certificate.

  • If it is not there, repeat using certlm.msc.

  1. Export and test the intermediate CA

  • Right-click the matching intermediate CA certificate → All Tasks → Export.

  • Export it as DER encoded binary X.509 (.CER).

  • Install that .CER file as a trusted CA certificate on one affected mobile device.

  • Reconnect the VPN.

Please make sure you export the matching intermediate CA, not the wildcard server certificate or the client certificate.

If the VPN works after installing this certificate, it would strongly confirm that the mobile device was missing the intermediate CA from the server certificate chain.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!