Skip to main content
aguerriero
Explorer
September 16, 2024
Solved

Server 2019 on hyper-v with Forticlient 7.2.5, ssl vpn not working

  • September 16, 2024
  • 8 replies
  • 3980 views

We have some hyper-v VMs that we upgraded from 7.2.3 to 7.2.5 forticlient. SSL VPN no longer works after upgrading.

We can repeat the problem by downgrading to 7.2.3 and then successfully connecting then upgrading to 7.2.5 and breaking it again.

we need to run 7.2.5 to fix a wild card FQDN issue with ztna destinations that we were experiencing on 7.2.3.

Best answer by aguerriero

TAC provided me with a 7.2.5.7679 Interim build that corrected everything. Waiting for the next GA to be released before I deploy everywhere. But the interim release is enough to at least get the 2019 devs up and running.

8 replies

samandeep
Staff
Staff
September 17, 2024

Hello @aguerriero

 

Could you provide the SSL VPN debug logs from your testing with FortiClient 7.2.5? Additionally, please confirm which authentication server is being utilized.


To collect the necessary logs, please run the following commands:


diag deb app sslvpnd -1
diag deb app fnbamd -1
diag deb console time en

diag deb en

To disable:

diag deb dis


These commands will enable debug logging for SSL VPN and provide valuable information for troubleshooting.

 

Thanks,

Amandeep

aguerriero
Explorer
September 17, 2024

This is the debug

2024-09-18 07:16:25 [310:root:19933]SSL state:before SSL initialization (192.168.25.200)
2024-09-18 07:16:25 [310:root:19933]SSL state:fatal decode error (192.168.25.200)
2024-09-18 07:16:25 [310:root:19933]SSL state:error:(null)(192.168.25.200)
2024-09-18 07:16:25 [310:root:19933]SSL_accept failed, 1:unexpected eof while reading
2024-09-18 07:16:25 [310:root:19933]Destroy sconn 0x7f9bf9e800, connSize=9. (root)
2024-09-18 07:16:25 [311:root:19934]allocSSLConn:310 sconn 0x7f9be59000 (0:root)
2024-09-18 07:16:25 [311:root:19934]SSL state:before SSL initialization (192.168.25.200)
2024-09-18 07:16:25 [311:root:19934]SSL state:fatal decode error (192.168.25.200)
2024-09-18 07:16:25 [311:root:19934]SSL state:error:(null)(192.168.25.200)
2024-09-18 07:16:25 [311:root:19934]SSL_accept failed, 1:unexpected eof while reading
2024-09-18 07:16:25 [311:root:19934]Destroy sconn 0x7f9be59000, connSize=1. (root)
2024-09-18 07:16:51 [306:root:19935]allocSSLConn:310 sconn 0x7f9be76000 (0:root)
2024-09-18 07:16:51 [306:root:19935]SSL state:before SSL initialization (192.168.25.200)
2024-09-18 07:16:51 [306:root:19935]SSL state:fatal decode error (192.168.25.200)
2024-09-18 07:16:51 [306:root:19935]SSL state:error:(null)(192.168.25.200)
2024-09-18 07:16:51 [306:root:19935]SSL_accept failed, 1:unexpected eof while reading
2024-09-18 07:16:51 [306:root:19935]Destroy sconn 0x7f9be76000, connSize=7. (root)
2024-09-18 07:16:51 [307:root:19935]allocSSLConn:310 sconn 0x7f9bf1d000 (0:root)
2024-09-18 07:16:52 [307:root:19935]SSL state:before SSL initialization (192.168.25.200)
2024-09-18 07:16:52 [307:root:19935]SSL state:fatal decode error (192.168.25.200)
2024-09-18 07:16:52 [307:root:19935]SSL state:error:(null)(192.168.25.200)
2024-09-18 07:16:52 [307:root:19935]SSL_accept failed, 1:unexpected eof while reading
2024-09-18 07:16:52 [307:root:19935]Destroy sconn 0x7f9bf1d000, connSize=7. (root)

aguerriero
Explorer
September 20, 2024

I opened a ticket with TAC and sent the full forticlient diagnostics and fortigate debugs. I will be having a screenshare session with an engineer later today.

aguerriero
aguerrieroAuthorAnswer
Explorer
October 2, 2024

TAC provided me with a 7.2.5.7679 Interim build that corrected everything. Waiting for the next GA to be released before I deploy everywhere. But the interim release is enough to at least get the 2019 devs up and running.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.