Skip to main content
adcapitaladmin
New Member
January 9, 2026
Solved

issue android VPN FORTICLIENT and FORTIOS v7.6.5 build 3651

  • January 9, 2026
  • 3 replies
  • 612 views

Hello everyone.

We have two FortiGate 100F devices configured in active/passive mode.
We are using six site-to-site IPsec tunnels, as well as remote users (Windows/Linux) who connect via FortiClient VPN.
In addition, there are users who connect from Android phones using FortiClient VPN for Android.
About a month ago, the FortiGate devices were automatically updated overnight to FORTIOS v7.6.5 build 3651.
After the update, external users lost the ability to connect via FortiClient VPN on Windows laptops.
After reconfiguring the VPN settings and switching back to DH group 5, Windows laptops were able to connect again.
However, FortiClient VPN on Android still cannot connect and returns an error.
On FortiClient for Android, only the following DH groups are available: 1, 2, 5, and 14.
I tried all of these DH groups one by one, but there was no improvement.
I tested this on multiple Android devices, and also tried the full FortiClient VPN version.
In all cases, I receive the same error in a loop (the connection attempt keeps repeating).

IKE V=root:Negotiate ISAKMP SA Error:
IKE V=root:0:3e35c70729dfedef/0000000000000000:8398: no SA proposal chosen
IKE V=root:0:!NEW_VPN_Orange_0: NAT keep-alive 39 XXX.XXX.XXX.XXX->172.21.3.17:4500.
IKE 0:!NEW_VPN_Orange_0:8389: out FF
IKE V=root:0:!NEW_VPN_Orange_0:8389: sent IKE MSG (keepalive): XXX.XXX.XXX.XXX:4500->172.21.3.17:4500, len=1, VRF=0, id=ff00000000000000/4100000000000000:55000000
IKE V=root:0:!NEW_VPN_Orange_0: NAT keep-alive XXX.XXX.XXX.XXX->172.21.3.17:4500.
IKE 0:!NEW_VPN_Orange_0:8389: out FF
(The real IP address has been changed to XXX)
before this update ( v7.6.5 build 3651) everything was working.
What else can we try to resolve this issue?

Thank you in advance

Best answer by HarryTran

It looks similar issue with: https://community.fortinet.com/t5/Support-Forum/IPsec-VPN-connection-issue-on-FortiClient-Android-after/m-p/425466#M281411
"This appears to have been already reported and is currently being investigated. The available workaround for now is to downgrade to 7.6.4 and below."

3 replies

KevinGue
Explorer II
January 9, 2026
IKE V=root:Negotiate ISAKMP SA Error:
IKE V=root:0:3e35c70729dfedef/0000000000000000:8398: no SA proposal chosen

This means your phase 1 configuration isn't matching. In the debugs there should be more information from the connection attempt regarding the proposals that the Android devices present and they need to match.

 

HarryTran
Staff
HarryTranAnswer
Staff
January 9, 2026

It looks similar issue with: https://community.fortinet.com/t5/Support-Forum/IPsec-VPN-connection-issue-on-FortiClient-Android-after/m-p/425466#M281411
"This appears to have been already reported and is currently being investigated. The available workaround for now is to downgrade to 7.6.4 and below."

adcapitaladmin
New Member
January 14, 2026

Thank you all for your help. I will wait for a decision from FortiGate.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!