Skip to main content
forti4sure
New Member
June 15, 2022
Question

SSL VPN blocks internet traffic (split dns connection) when connected but ONLY for a specific user

  • June 15, 2022
  • 3 replies
  • 1957 views

So, MS Surfaces and Forticlient VPN have been one of my Nemesis' at a specific site for a specific user.

 

Previously when we upgraded his Surface Pro a few years ago, when he'd connect via SSL VPN, internet connectivity would slow way down, at that time we were using the free Forticlient and got permission from Fortinet to get a trial version of the paid client to see if issue was FC related.  After a lot of back and forth, the issue was resolved and I and the user was happy.  I am going to review that ticket again and make sure there wasn't some kind of work around put in place that may be affecting this.

 

Fast forward to the beginning of June, we replaced his Surface and used our typical tool (TransWiz) to transfer his existing Windows profile to new machine, he was happy.  A few days later I get advised that when FortClient Free VPN is connected ALL internet traffic that's not across the link stops, example if I have a remote session with him I loose connectivity.  Also he can't use Zoom or email etc.  None of this is normal with his prior machine  and this does not occur for the 30 other users either (mix of both Mac and PC laptops and other Surfaces)

 

For troubleshooting, removed and reinstalled FC, then installed latest version from 2 weeks ago, no change.  Further testing indicates this ONLY occurs with his AD specific VPN user login and it doesn't matter which Windows Profile we use, his, a local admin or domain admin, all experience the same issue.  While logged into any windows profile, if I use a different user for the FC connection, no issues are all. It works as expected and the split connection also works as expected.

 

Background:

All SSL VPN Connections require MFA, when connection comes in, the firewall (100E) checks the internal radius server which checks AD and then forwards the request to external MFA server, the MFA app on the iPhone then requests approval and if approved, the VPN connection is allowed.

 

Any ideas or suggestions?

 

 

3 replies

Anthony_E
Staff
Staff
June 18, 2022

Hello forti4sure,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Best Regards
Contributor III
June 19, 2022

Hi there,

Thank you for the explaination.
From my understanding, you already isolate the issue and its more to username issue.
On AD server, please verify if that username has been locked due too many attempt or expired. You may consider to reset the password too.

 

Hope that helps.

krobrelus
New Member
September 1, 2026

I use FortiClient with SSL-VPN in 2 environments, Windows and macOS. On Windows, the internet works perfectly, but when I use it on macOS, I lose my internet connection — only the VPN works. I've already tried everything and can't fix it.


SSL-VPN (OFF):

en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500

options=6460<TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>

ether 7c:f3:4d:f0:2c:b7

inet6 fe80::59:9023:fc29:dac4%en0 prefixlen 64 secured scopeid 0xe 

inet 192.168.68.101 netmask 0xfffffc00 broadcast 192.168.71.255

nd6 options=201<PERFORMNUD,DAD>

media: autoselect

status: active

 

SSL-VPN (ON):

 

utun6: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1340

options=6460<TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>

inet 10.212.134.16 --> 10.212.134.16 netmask 0xffffffff

inet6 fe80::7ef3:4dff:fef0:2cb7%utun6 prefixlen 64 scopeid 0x18 

inet6 fc00:52b8:9ccd:c70:2a8:a78a:16:28be prefixlen 64 

nd6 options=201<PERFORMNUD,DAD>

 

paulo@MacBook-Pro-de-PAULO ~ % netstat -rn | grep default

default            192.168.68.1       UGScg                 en0       

default            link#24            UCSIg               utun6       

default                                 fe80::%utun0                            UGcIg               utun0       

default                                 fe80::%utun1                            UGcIg               utun1       

default                                 fe80::%utun2                            UGcIg               utun2       

default                                 fe80::%utun3                            UGcIg               utun3       

default                                 fe80::%utun4                            UGcIg               utun4       

default                                 fe80::%utun5                            UGcIg               utun5       

default                                 fc00:fafa:1dd:feb::                     UGcIg               utun6       

paulo@MacBook-Pro-de-PAULO ~ % netstat -rn | grep default

default            192.168.68.1       UGScg                 en0       

default                                 fe80::%utun0                            UGcIg               utun0       

default                                 fe80::%utun1                            UGcIg               utun1       

default                                 fe80::%utun2                            UGcIg               utun2       

default                                 fe80::%utun3                            UGcIg               utun3       

default                                 fe80::%utun4                            UGcIg               utun4       

default                                 fe80::%utun5                            UGcIg               utun5
 

paulo@MacBook-Pro-de-PAULO ~ % ping 8.8.8.8

PING 8.8.8.8 (8.8.8.8): 56 data bytes

64 bytes from 8.8.8.8: icmp_seq=0 ttl=115 time=11.883 ms

64 bytes from 8.8.8.8: icmp_seq=1 ttl=115 time=6.085 ms

64 bytes from 8.8.8.8: icmp_seq=2 ttl=115 time=7.709 ms

64 bytes from 8.8.8.8: icmp_seq=3 ttl=115 time=6.614 ms

64 bytes from 8.8.8.8: icmp_seq=4 ttl=115 time=8.752 ms

64 bytes from 8.8.8.8: icmp_seq=5 ttl=115 time=11.232 ms

^C

--- 8.8.8.8 ping statistics ---

6 packets transmitted, 6 packets received, 0.0% packet loss

round-trip min/avg/max/stddev = 6.085/8.713/11.883/2.188 ms

paulo@MacBook-Pro-de-PAULO ~ % scutil --dns

DNS configuration

 

resolver #1

  nameserver[0] : 100.0.65.2

  nameserver[1] : 100.0.65.221

  flags    : Request A records

  reach    : 0x00000003 (Reachable,Transient Connection)

 

resolver #2

  domain   : local

  options  : mdns

  timeout  : 5

  flags    : Request A records

  reach    : 0x00000000 (Not Reachable)

  order    : 300000

 

resolver #3

  domain   : 254.169.in-addr.arpa

  options  : mdns

  timeout  : 5

  flags    : Request A records

  reach    : 0x00000000 (Not Reachable)

  order    : 300200

 

resolver #4

  domain   : 8.e.f.ip6.arpa

  options  : mdns

  timeout  : 5

  flags    : Request A records

  reach    : 0x00000000 (Not Reachable)

  order    : 300400

 

resolver #5

  domain   : 9.e.f.ip6.arpa

  options  : mdns

  timeout  : 5

  flags    : Request A records

  reach    : 0x00000000 (Not Reachable)

  order    : 300600

 

resolver #6

  domain   : a.e.f.ip6.arpa

  options  : mdns

  timeout  : 5

  flags    : Request A records

  reach    : 0x00000000 (Not Reachable)

  order    : 300800

 

resolver #7

  domain   : b.e.f.ip6.arpa

  options  : mdns

  timeout  : 5

  flags    : Request A records

  reach    : 0x00000000 (Not Reachable)

  order    : 301000

 

DNS configuration (for scoped queries)

 

resolver #1

  nameserver[0] : 100.0.65.2

  nameserver[1] : 100.0.65.221

  if_index : 14 (en0)

  flags    : Scoped, Request A records

  reach    : 0x00000002 (Reachable)

 

resolver #2

  nameserver[0] : 100.0.65.2

  nameserver[1] : 100.0.65.221

  if_index : 24 (utun6)

  flags    : Scoped, Request A records, Request AAAA records

  reach    : 0x00000003 (Reachable,Transient Connection)

paulo@MacBook-Pro-de-PAULO ~ % scutil --dns | grep 'resolver #1' -A 5

resolver #1

  nameserver[0] : 100.0.65.2

  nameserver[1] : 100.0.65.221

  flags    : Request A records

  reach    : 0x00000003 (Reachable,Transient Connection)

 

--

resolver #1

  nameserver[0] : 100.0.65.2

  nameserver[1] : 100.0.65.221

  if_index : 14 (en0)

  flags    : Scoped, Request A records

  reach    : 0x00000002 (Reachable)

paulo@MacBook-Pro-de-PAULO ~ % nslookup google.com 100.0.65.2

;; connection timed out; no servers could be reached

 

paulo@MacBook-Pro-de-PAULO ~ % sudo nano /etc/resolv.conf 

Password:

paulo@MacBook-Pro-de-PAULO ~ % cat /etc/resolv.conf 

#

# macOS Notice

#

# This file is not consulted for DNS hostname resolution, address

# resolution, or the DNS query routing mechanism used by most

# processes on this system.

#

# To view the DNS configuration used by this system, use:

#   scutil --dns

#

# SEE ALSO

#   dns-sd(1), scutil(8)

#

# This file is automatically generated.

#

nameserver 100.0.65.2

nameserver 100.0.65.221

nameserver 8.8.8.8

nameserver 1.1.1.1

paulo@MacBook-Pro-de-PAULO ~ % nslookup google.com 100.0.65.2

;; connection timed out; no servers could be reached

 

paulo@MacBook-Pro-de-PAULO ~ % 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!