Skip to main content
vindegosh
New Member
June 10, 2026
Question

Tracking down a forticlient profile config anomoly

  • June 10, 2026
  • 1 reply
  • 33 views

We have multiple IPSEC VPN dial up customer sites with SAML.

One of our clients sites, requires NAT to be turned OFF in the Forticlient profile to connect, and all the rest require it ON. Mostly it's the same or similar ISP, NAT in the Phase 1 policy on the Firewalls are set to the same on the two examples I tested, so I don't think it's that.

FortiOS 7.2.13 on a 60F for both.

Any ideas where or how I can figure out why this setting requirement differs between this site and the others?

TIA

    1 reply

    AEK
    SuperUser
    SuperUser
    June 10, 2026

    I guess you mean NATT (NAT Traversal).

    When you use NATT it is over UDP (or TCP if forced), while without NATT it uses ESP (IP 50).

    If you are sure there is no NAT then probably some of your ISPs are blocking IP 50.

    AEK