Skip to main content
FKribs
New Member
July 31, 2014
Solved

VPN stuck at status 98%

  • July 31, 2014
  • 34 replies
  • 825772 views
We are running Windows Server 2012 R2. We have installed the most recent FortiNet client (vpn only), version 5.2.0.0591. We have configured an SSL-VPN connection. When we click on the " connect" button, the status progresses all the way to 98% and then hangs. We have disabled the windows firewall, do not have any anti virus software installed, no group policies are being applied, and no other applications are running when we attempt to make the VPN connection. Thanks for helping!
    Best answer by denniswong34

    Hi All,

     

    I just fix it by apply this fix and re-install fortigate client.

    https://skydrive.live.com/redir?resid=86BDD34D41D3E179!2065&authkey=!AAeyjPB4O4uVxek

     

    You may find the detail from this forums. Hope this could help you all. Thanks.

    https://supportforums.cisco.com/discussion/11682811/anyconnect-msi-installation-failed-windows-7

    34 replies

    luca_comes
    New Member
    May 13, 2015

    Hi Paul,

    thank you for your reply. yes all the adapters seem ok in the device manager, anyway I tried to reinstall them but the behavoiur doesn't change. The strange thing is that until 2 weeks ago all the vpns were working fine, suddenly after the 1 of may they don't work anymore while other ssl vpns (Cisco anyconect for example) are working fine. No updates were made and no network modification, also some client are working fine (mine is one of them) and many others no. I don't know what to check the log file can't help and I can't read log file from the fortinet appliance.

     

    Luca

    trinityhealth
    New Member
    May 22, 2015

    I was having the same issue, it turned out to be an issue with vpnike.dll. Ultimately the remote access connection manger service would not start. This hotfix from microsoft fixed the issue http://hotfixv4.microsoft.com/Windows%207/Windows%20Server2008%20R2%20SP1/sp2/Fix463202/7600/free/465939_intl_i386_zip.exe)

    daccu
    New Member
    July 24, 2015

    trinityhealth wrote:

    I was having the same issue, it turned out to be an issue with vpnike.dll. Ultimately the remote access connection manger service would not start. This hotfix from microsoft fixed the issue http://hotfixv4.microsoft.com/Windows%207/Windows%20Server2008%20R2%20SP1/sp2/Fix463202/7600/free/465939_intl_i386_zip.exe)

     

    Can you point me to the KB article for that hotfix?  I couldn't seem to find it based on the Fix # or filename.  I'd like to know what the issue with the .dll is and what the hotfix does.  Thanks!

    Asmyldz1
    New Member
    September 17, 2015

    Hi Guys,

    I solved problem. First you must open "Device Manger".

    Second click network adapters.

    Third look for "yellow cautions". Uninstall all have yellow caution adapters.

    For uninstall you must look microsoft support site. 

    This has solved problem. Have nice days.

     

    Krish
    New Member
    January 22, 2016

    I am facing the same issue, VPN not able to connect through FortiClient. I am using latest version 5.4.0.0780, windows 10 64bit. Any suggestions to resolve this would be highly appreciated. Please see the below log file

     

    Thanks

     

    1/22/2016 9:38:31 AM Debug VPN FortiSslvpn: 8244: fortissl_getstatus(1361) called 1/22/2016 9:38:31 AM Debug ESNAC dwSilentReg false 1/22/2016 9:38:31 AM Debug ESNAC bFirstKA true 1/22/2016 9:38:31 AM Debug ESNAC Start searching for FGT 1/22/2016 9:38:31 AM Debug AntiVirus Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:31 AM Debug ESNAC Searching Default GW 1/22/2016 9:38:33 AM Debug ESNAC Timeout in select in SocketConnect 1/22/2016 9:38:33 AM Debug ESNAC Socket connect failed 1/22/2016 9:38:33 AM Debug ESNAC 172.30.202.1:8013, Secondary - 0 1/22/2016 9:38:33 AM Debug ESNAC Searching Default GW 1/22/2016 9:38:33 AM Debug AntiVirus Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:33 AM Debug AntiVirus (repeated 1 times in last 0 sec) Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:34 AM Debug ESNAC Timeout in select in SocketConnect 1/22/2016 9:38:34 AM Debug ESNAC Socket connect failed 1/22/2016 9:38:34 AM Debug ESNAC 192.168.8.1:8013, Secondary - 0 1/22/2016 9:38:34 AM Debug ESNAC End searching for FGT 1/22/2016 9:38:34 AM Debug VPN FortiSslvpn: CSslvpnBase::RefreshConnection() Called. 1/22/2016 9:38:34 AM Debug AntiVirus Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:49 AM Debug AntiVirus (repeated 12 times in last 15 sec) Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:52 AM Debug ESNAC dwSilentReg false 1/22/2016 9:38:52 AM Debug ESNAC bFirstKA true 1/22/2016 9:38:52 AM Debug ESNAC Start searching for FGT 1/22/2016 9:38:52 AM Debug ESNAC Searching Default GW 1/22/2016 9:38:52 AM Debug AntiVirus Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:52 AM Debug AntiVirus (repeated 17 times in last 1 sec) Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:53 AM Debug ESNAC Timeout in select in SocketConnect 1/22/2016 9:38:53 AM Debug ESNAC Socket connect failed 1/22/2016 9:38:53 AM Debug ESNAC 172.30.202.1:8013, Secondary - 0 1/22/2016 9:38:53 AM Debug ESNAC Searching Default GW 1/22/2016 9:38:53 AM Debug AntiVirus Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:53 AM Debug AntiVirus (repeated 2 times in last 1 sec) Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F 1/22/2016 9:38:53 AM Debug ESNAC Timeout in select in SocketConnect 1/22/2016 9:38:53 AM Debug ESNAC Socket connect failed 1/22/2016 9:38:53 AM Debug ESNAC 192.168.8.1:8013, Secondary - 0 1/22/2016 9:38:53 AM Debug ESNAC End searching for FGT 1/22/2016 9:38:55 AM Debug AntiVirus Cannot send message to the driver(5476:1880). ErrorCode=0x0000001F

    JordanAtParkRoadSolu
    New Member
    January 22, 2016

    Hello Everyone,   I'm migrating over to Fortinet and ran accross this problem. I've listed a few possible solutions, the first of which worked for me (Windows 8.1 Pro).   Notes: All solutions below came from the following reddit thread. Fortinet now has a KB article that re-iterates my "option 3" below.       Option 1 (Worked For Me):   1) Open Network Connections  2) Note the “fortissl” connection will have the device message “Unavailable - device missing”  3) Open the properties for this connection  4) On the “General” tab: 

    a. Uncheck the “Modem Removed – Unavailable device ()” device  b. Check the “ISDN channel - PPPoP WAN Adapter” device  c. Click the up arrow on the right to move the “ISDN channel - PPPoP WAN Adapter” to the top of the list  d. Set the phone number for the “ISDN channel - PPPoP WAN Adapter” to “1” (without the quotes) 

    5) Click “OK” to close the “fortissl” properties  6) The “fortissl” connection should now appear gray with the device message “PPPoP WAN Adapter” and a status of “Disconnected”  7) You should now be able to successfully establish an SSL VPN connection   Option 2:

     

    1) remove all fortigate instalations

    2) run CCleaner to remove any remaining files and registry garbage.

    3) Reboot

    4) Reinstall the latest version of the forticlient. (latest not strictly needed for this)

    5) it will still be broken.

    6) Go to device manager

    7) under network adapters, if you are having the same issue we are, you will see several miniports in a degraded state, with yellow error flags.

    8) this is the important part for each one, you need to deliberately misconfigure it before removing it.

    [ul]
  • Do this by selecting update driver software>browse locally>pick from my computer.
  • Uncheck the box that says "show compatible hardware" Point it at any of the microsoft generic network drivers. Literally any driver will do as long as it is wrong.
  • Once this applies (it will yell at you about not working) it will rename the miniport to whatever driver you selected.
  • At this point you can uninstall the device. Do this for every damaged miniport, and then reboot one more time.[/ul]

    "This did it for us in a recent occurrence of this situation." 

        Option 3: Repair Tool   For this particular issue, "version 1" and "version 2" of the tool is purported to work under different (undefined) circumstances. UpdateFortinet has written a KB article recommended procedures for the tool below.    https://www.vpnhosting.cz/index.php/clanky/wan-miniport-repair-tool-solve-vpn-and-dial-up-error-code-720-and-similar-ppperrors.html

     

  • greylander
    New Member
    January 27, 2016

    Hi,

    I seem to be experiencing this problem, or very similar problem. 

     

    Forticlient hangs at 98% while connecting.  But this only happen occasionally -- especially if the connect dropped for some reason and I try to connect again (possibly every time this happens).

     

    I am able to get Forticlient to connect if I reboot my machine.  So maybe this is not the identical problem discussed here.  Sometimes it gives the "You already have an open SSL VPN connection" warning, but not always. Either way, it stops at 98%, after a minute or so, it just clears the login fields of the forticlient window as if nothing had ever happened.

     

    Rebooting my machine "resets" something and makes connection possible.  But this is a frustrating workaround.  

     

    Is there a process or service I should be able to restart that would have the same effect as rebooting?

    ss198939
    New Member
    January 28, 2016
    I have also faced this issue. This is problem with window. If u will use same client in another window it will work. My problem.was resolved by formating window. And also check.if u r using right version of client.check in support.fortinet.com.
    adnan
    New Member
    January 28, 2016

    Dear, We are having problem regarding VPN authentication. Due to security concern, we request our client to purchase public IP from any vendor (DSL, Fiber etc). After taking public IP information from client, our team will bind this public IP for VPN connectivity so that authentic user can connect (who has public IP).

     

     

    a_tallone
    New Member
    February 28, 2016

    Hi everyone!

     

    I'm having the same issue (stuck 98%) but apparently all ok about network devices. 

     

    Version 5.4.0.0780

     

    Here's my log:

     

    28/02/2016 11:08:17 Warning Console id=96870 user=alby msg="Logs were cleared" 28/02/2016 11:08:20 Notice VPN id=96573 user=alby msg="VPN before logon was disabled" vpntype=ipsec 28/02/2016 11:08:20 Notice ESNAC id=96951 user=alby msg="Endpoint control policy synchronization was enabled" 28/02/2016 11:08:20 Notice Console id=96880 user=alby msg="User disabled WAN Acceleration" 28/02/2016 11:08:20 Warning SSOMA id=96982 user=alby msg="Single Sign-On Mobility Agent was disabled" 28/02/2016 11:08:20 Warning Console id=96840 user=alby msg="Fortiproxy is disabled" 28/02/2016 11:08:20 Debug Scheduler GUI change event 28/02/2016 11:08:22 Debug Config Comments removed from (C:\Users\alby\AppData\Local\Temp\tmp_connect_fct.cnf) 28/02/2016 11:08:22 Debug Scheduler GUI change event 28/02/2016 11:08:22 Debug ESNAC PIPEMSG_CMD_ESNAC_STATUS_RELOAD_CONFIG 28/02/2016 11:08:22 Debug ESNAC PIPEMSG_CMD_ESNAC_STATUS_UPDATE_PREFERRED_FGT 28/02/2016 11:08:24 Debug Scheduler GUI change event 28/02/2016 11:08:24 Debug Update Update task is called with dwSession=-1 28/02/2016 11:08:24 Debug Update forticlient.fortinet.net 28/02/2016 11:08:24 Debug Update start_update_thread() called 28/02/2016 11:08:24 Debug Update Impersonated=0 28/02/2016 11:08:24 Debug Update update started... 28/02/2016 11:08:24 Debug Update update process sending request: 00000000FSCI00000000000000000000 28/02/2016 11:08:24 Debug Update update process sending request: 00000000FDNI00000000000000000000 28/02/2016 11:08:24 Debug Update update process sending request: 01000000FECT00000000000000000000 28/02/2016 11:08:24 Debug Update update process sending request: 05004000FVEN00800054009999999999 28/02/2016 11:08:24 Debug Update update process sending request: 05004000FCBN00000000009999999999 28/02/2016 11:08:24 Debug Update updatetask get virus info file failed 28/02/2016 11:08:25 Debug Update update process received object(1 of 3): FCPR 28/02/2016 11:08:25 Debug Update update process received object(2 of 3): FDNI 28/02/2016 11:08:25 Debug Update update process received object(3 of 3): FECT 28/02/2016 11:08:25 Debug Update update done 28/02/2016 11:08:25 Debug Scheduler FortiTrayApp : Received WM_USER_UPDATE_SUCCESS message, lParam=0x1 28/02/2016 11:08:25 Debug Update update thread exit 28/02/2016 11:08:25 Debug Update No update is available. 28/02/2016 11:08:25 Debug Scheduler GUI change event 28/02/2016 11:08:28 Debug Scheduler handle_processtermination() called 28/02/2016 11:08:28 Debug Scheduler child process terminates normally 28/02/2016 11:08:28 Debug Scheduler handle_processtermination() called 28/02/2016 11:08:28 Debug Scheduler child process terminates normally 28/02/2016 11:08:31 Debug ESNAC dwSilentReg false 28/02/2016 11:08:31 Debug ESNAC bFirstKA true 28/02/2016 11:08:31 Debug ESNAC Start searching for FGT 28/02/2016 11:08:31 Debug ESNAC Searching Default GW 28/02/2016 11:08:32 Debug ESNAC Timeout in select in SocketConnect 28/02/2016 11:08:32 Debug ESNAC Socket connect failed 28/02/2016 11:08:32 Debug ESNAC 192.168.1.1:8013, Secondary - 0 28/02/2016 11:08:32 Debug ESNAC End searching for FGT 28/02/2016 11:08:33 Debug VPN FortiSslvpn: 7376: fortissl_disconnect() called 28/02/2016 11:08:35 Debug VPN FortiSslvpn: 7376: tunnel_close() called 28/02/2016 11:08:35 Debug VPN FortiSslvpn: 7376: sock_close() called:-1 28/02/2016 11:08:35 Debug VPN FortiSslvpn: SSL VPN Tunnel is Disconnected ********* 28/02/2016 11:08:35 Debug VPN FortiSslvpn: Broken pipe! Client is exited (2) - Disconnect. 28/02/2016 11:08:35 Debug VPN FortiSslvpn: 7376: fortissl_disconnect() called 28/02/2016 11:08:35 Debug VPN FortiSslvpn: Init:ConnectNamedPipe(): Wait(hEventOverLapped) OK. 28/02/2016 11:08:35 Debug VPN FortiSslvpn: before ConnectNamedPipe 28/02/2016 11:08:35 Debug VPN FortiSslvpn: Init:ConnectNamedPipe(): rc=0, err=997 28/02/2016 11:08:35 Debug VPN FortiSslvpn: _ReceiveMessage: (000003E8) 28/02/2016 11:08:37 Debug VPN FortiSslvpn: 7376: tunnel_close() called 28/02/2016 11:08:37 Debug VPN FortiSslvpn: 7376: sock_close() called:-1 28/02/2016 11:08:37 Debug VPN FortiSslvpn: SSL VPN Tunnel is Disconnected ********* 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig() called 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig() connectionName:work 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig() called 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig() cookie: c3nCv6lcKLf9dF1PBcT8Z4h07JFm7PTOFWpz/WQmU5978WELGbZlng5osAKxMMpi%0aldnwoMbmuqlO7HA1G/FIn6D2bGl0eTupZUb7E+gxwqNK9fn8cev3V0M2gGv174ju%0a1zu2YMpkwoRVBS0RGbKww9l/ZGgMNm1Oxi3Mccj87HRaK6fOA/Q52IzzM5a8Eb9B%0aK2I/GiYSiYyzkQhApx2gNQ==%0a 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig() hostname:vpn.oliocarli.it port:10443 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig() called 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig() splittunnel info:172.16.1.11/255.255.255.255,172.16.1.38/255.255.255.255,172.16.1.20/255.255.255.255,172.16.1.14/255.255.255.255,172.16.1.25/255.255.255.255,172.16.0.0/255.255.0.0,172.17.20.0/255.255.255.0 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig() called 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setconfig(): reset proxy 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_setversion() called:1 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: fortissl_connect() called. (ipv6=0, fct=1) 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: Resolve server 'vpn.oliocarli.it(10443)' = 213.204.2.2:10443/[0000:0000:0000:0000:0000:0000:0000:0000]:0. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: Setting route to 213.204.2.2 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: on 192.168.1.1 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: get_interface_metric() called, local index:6 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: metric: 10 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: CreateIpForwardEntry(dest=0202ccd5 mask=ffffffff next=0101a8c0) 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7500: IPv4SetRouteToFgt(00B4380C, 00B4384C)=0 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: tunnel_thread() called 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7508: ras_thread() called 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: * tunnel opened 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: SSL authentification using files: C:\Program Files (x86)\Fortinet\FortiClient\fortisslcacert.pem C:\Program Files (x86)\Fortinet\FortiClient\fortisslclient.crt C:\Program Files (x86)\Fortinet\FortiClient\fortisslclient.key 28/02/2016 11:08:38 Debug VPN (repeated 1 times in last 0 sec) FortiSslvpn: 7620: SSL authentification using files: C:\Program Files (x86)\Fortinet\FortiClient\fortisslcacert.pem C:\Program Files (x86)\Fortinet\FortiClient\fortisslclient.crt C:\Program Files (x86)\Fortinet\FortiClient\fortisslclient.key 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: * SSL OK 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: * tunnel pending ... 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: info: tunnel_start_to_fgt(00B33F80) called. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: connecting tunnel (0) ... 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: connecting TCP ... 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: TCP_NODELAY value:1 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: WSAConnect(1,0), r=-1, e=10035. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: Socket event signaled! 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: connecting SSL ... 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: call back called! 28/02/2016 11:08:38 Debug VPN (repeated 2 times in last 0 sec) FortiSslvpn: 7620: call back called! 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: SSL connected 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoXmlConfig]... 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: info: SslBlockingWrite(00B9A020, 02046E90, 303, 10000) called. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoXmlConfig]: GET remote/fortisslvpn_xml ... (send 303 of 303 bytes): GET /remote/fortisslvpn_xml HTTP/1.1 Host: sslvpn Cookie: SVPNCOOKIE=c3nCv6lcKLf9dF1PBcT8Z4h07JFm7PTOFWpz/WQmU5978WELGbZlng5osAKxMMpi%0aldnwoMbmuqlO7HA1G/FIn6D2bGl0eTupZUb7E+gxwqNK9fn8cev3V0M2gGv174ju%0a1zu2YMpkwoRVBS0RGbKww9l/ZGgMNm1Oxi3Mccj87HRaK6fOA/Q52IzzM5a8Eb9B%0aK2I/GiYSiYyzkQhApx2gNQ==%0a ---- . 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: info: SslBlockingRead(00B9A020, 02044E18, 8191, 10000) called. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoXmlConfig]: GET remote/fortisslvpn_xml ... (received 1169 bytes): HTTP/1.1 200 OK Date: Sun, 28 Feb 2016 10:08:40 GMT Set-Cookie: SVPNCOOKIE=c3nCv6lcKLf9dF1PBcT8Z4h07JFm7PTOFWpz/WQmU5978WELGbZlng5osAKxMMpi%0aldnwoMbmuqlO7HA1G/FIn6D2bGl0eTupZUb7E+gxwqNK9fn8cev3V0M2gGv174ju%0a1zu2YMpkwoRVBS0RGbKww+ubPNURQrBdgHp7RrW1R/Dk5YDZGLGaRqs5KjPpvUmS%0am/wtv0BJrYvYjyJShF2aDA==%0a; path=/; secure; httponly Transfer-Encoding: chunked Content-Type: text/xml X-Frame-Options: SAMEORIGIN <?xml 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoXmlConfigEx]: Xml= <?xml version='1.0' encoding='utf-8'?><sslvpn-tunnel ver='1'><fos platform='FG200B' major='5' minor='02' patch='6' build='0711' branch='711' /><client-config save-password='off' keep-alive='off' auto-connect='off' /><ipv4><dns ip='172.16.1.38' /><dns ip='172.16.1.20' /><assigned-addr ipv4='192.168.127.1' /><split-tunnel-info><addr ip='172.16.1.11' mask='255.255.255.255' /><addr ip='172.16.1.38' mask='255.255.255.255' /><addr ip='172.16.1.20' mask='255.255.255.255' / 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoXmlConfig]: dnsSuffixes = 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoLicCheck]... 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: info: SslBlockingWrite(00B9A020, 02046E90, 751, 10000) called. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoLicCheck]: GET /remote/licensecheck ... (usr=tallonea@carli, send 751 of 751 bytes): GET /remote/licensecheck HTTP/1.1 Host: sslvpn Cookie: SVPNCOOKIE=c3nCv6lcKLf9dF1PBcT8Z4h07JFm7PTOFWpz/WQmU5978WELGbZlng5osAKxMMpi%0aldnwoMbmuqlO7HA1G/FIn6D2bGl0eTupZUb7E+gxwqNK9fn8cev3V0M2gGv174ju%0a1zu2YMpkwoRVBS0RGbKww9l/ZGgMNm1Oxi3Mccj87HRaK6fOA/Q52IzzM5a8Eb9B%0aK2I/GiYSiYyzkQhApx2gNQ==%0a FCC_License: 5645523D310A4643545645523D352E342E302E303738300A5549443D464530383138344437303843343534344136 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: info: SslBlockingRead(00B9A020, 02043E10, 8191, 10000) called. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoLicCheck]: GET /remote/licensecheck ... (received 659 bytes): HTTP/1.1 200 OK Date: Sun, 28 Feb 2016 10:08:40 GMT FCC_Status: 10 FCC_Message: 5645523d310a434f44453d300a Transfer-Encoding: chunked Content-Type: text/html X-Frame-Options: SAMEORIGIN <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="cache-control" content="no-cache"> <meta http-equiv="cache-control" content="must-rev 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: [DoLicCheck]: After DecodeLicenseResult(): s=10, r=0, message= 5645523d310a434f44453d300a VER=1 CODE=0 ---- 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: ===>send to login, ret=331 buf=GET /remote/sslvpn-tunnel?dns0=192.168.1.1&dns1=8.8.4.4 HTTP/1.1 Host: sslvpn Cookie: SVPNCOOKIE=c3nCv6lcKLf9dF1PBcT8Z4h07JFm7PTOFWpz/WQmU5978WELGbZlng5osAKxMMpi%0aldnwoMbmuqlO7HA1G/FIn6D2bGl0eTupZUb7E+gxwqNK9fn8cev3V0M2gGv174ju%0a1zu2YMpkwoRVBS0RGbKww9l/ZGgMNm1Oxi3Mccj87HRaK6fOA/Q52IzzM5a8Eb9B%0aK2I/GiYSiYyzkQhApx2gNQ==%0a 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: info: ssl_connect -> Set XmlConfig OK. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7620: info: tunnel_up(00B33F80, 1) called. 28/02/2016 11:08:39 Debug VPN FortiSslvpn: 7508: info: ras_loop(), XmlConfig OK. 28/02/2016 11:08:39 Error VPN FortiSslvpn: 7508: RasGetEntryDialParams returns 1058 : 28/02/2016 11:08:40 Debug VPN FortiSslvpn: 7640: monitor_thread() called 28/02/2016 11:08:40 Debug VPN FortiSslvpn: 7640: register_route_change_event_ipv4() called 28/02/2016 11:08:40 Debug VPN FortiSslvpn: 7640: ras_thread quit 28/02/2016 11:08:40 Error VPN FortiSslvpn: 7500: failed to create one of the threads 28/02/2016 11:08:40 Debug VPN FortiSslvpn: g_dwKeepRunningFlag = 0. 28/02/2016 11:08:40 Debug VPN FortiSslvpn: 7640: waiting for tunnel thread ... 28/02/2016 11:08:44 Debug VPN FortiSslvpn: 5232: fortissl_getstatus(2049) called 28/02/2016 11:08:44 Debug VPN FortiSslvpn: 7640: stopping tunnel thread 28/02/2016 11:08:44 Debug VPN FortiSslvpn: 7640: tunnel_close() called 28/02/2016 11:08:44 Debug VPN FortiSslvpn: 7640: sock_close() called:1032 28/02/2016 11:08:44 Debug VPN FortiSslvpn: 7640: Monitor thread terminated 28/02/2016 11:08:44 Debug VPN FortiSslvpn: 7640: RestartDnschcheService() -> (tid=6180) 28/02/2016 11:08:44 Debug VPN FortiSslvpn: 6180: RestartDnscacheServiceProc() running ... 28/02/2016 11:08:44 Debug VPN FortiSslvpn: 6180: RestartDnscacheServiceProc()->QueryServiceStatus(3): ss=1 28/02/2016 11:08:46 Debug VPN FortiSslvpn: 6180: RestartDnscacheServiceProc() end. 28/02/2016 11:08:51 Debug ESNAC dwSilentReg false 28/02/2016 11:08:51 Debug ESNAC bFirstKA true 28/02/2016 11:08:51 Debug ESNAC Start searching for FGT 28/02/2016 11:08:51 Debug ESNAC Searching Default GW 28/02/2016 11:08:52 Debug ESNAC Timeout in select in SocketConnect 28/02/2016 11:08:52 Debug ESNAC Socket connect failed 28/02/2016 11:08:52 Debug ESNAC 192.168.1.1:8013, Secondary - 0 28/02/2016 11:08:52 Debug ESNAC End searching for FGT

     

    MikePruett
    New Member
    July 5, 2016

    Fabian,

     

    We have this issue off and on as well. My SE's and TAC's have not been able to determine a root cause for our solution. We have to try a mixture of the previously mentioned solutions in order to resolve.

     

    It is annoying but at least there is a "work around". Hopefully a solution appears soon.

    torenhof
    Explorer II
    July 20, 2016

    Hello,

     

    I've been experiencing this on Win 8.0

    The KB: http://kb.fortinet.com/kb/documentLink.do?externalID=FD36630

    solved the issue.

     

    Regards

    Gerrit

    pimu
    New Member
    August 10, 2016

    Hi

    I just experience on my Windows 10 all what greylander says (see #66 above).

    I see all what he says to see, except the "You already have an open SSL VPN connection" warning, and I agree with him about the annoying workaround of restarting the machine

     

    I would only add that I see often DNS not working after disconnection and what I see in the log of forticlient during the minute of wait before timeout:

    ..
    15:21:44     Debug   VPN     FortiSslvpn: 15092: poll_recv_ssl -> SSL_ERROR_WANT_READ
    15:21:44     Debug   VPN     FortiSslvpn: 15092: poll_recv_ssl return 0 bytes, read after timeout
    15:21:44     Debug   VPN     FortiSslvpn: 15092: [tunnel_loop_read_socket] wait for socket event
    15:21:44     Debug   VPN     FortiSslvpn: 15092: wait for socket event timeout, try to do a read
    15:21:44     Debug   VPN     FortiSslvpn: 15092: [SSL-IN] buf size = 65540, ptr = 0, space = 65540
    15:21:44     Debug   VPN     FortiSslvpn: 15092: [SSL-IN] len = -1
    15:21:44     Debug   VPN     FortiSslvpn: 15092: poll_recv_ssl -> SSL_ERROR_WANT_READ
    ..

     

    Regards

    P.

    Filonowst
    New Member
    October 11, 2016

    98% is the point where the FortiGate is supposed to issue the IP address to the VPN client. At this point, your credentials have already been verified, etcetera. Check your IP address settings and make sure they are correct. Post them here if you're not sure. Is this for all client computers or just particular ones? Sometimes when a client is disconnected suddenly and the connection is not properly terminated, something hangs on the client machine and when you try to reconnect you can't get past 98%. An OS reboot fixes it (despite searching, I haven't been able to locate the exact process, service, or device to reset the hung connection without a full reboot).

    NetCoLoGn
    New Member
    October 17, 2016

    Hi,

     

    we're facing the same Issue with FortiClient 5.4.1.0840.

    Additional to that - sometimes we get connected and after that alle network drivers crash down.

    Windows 10 Ver. 1607

    A reboot helps for max. 1 hour - then the same things happen again.

     

    Firewall is also shut down, same as Win Defender - we're Using Avira AntiVir.

     

    Regards

     

     

    finjoe
    New Member
    November 13, 2017

    sounds like server end problem, did you try with update?

    Sebastiaan_Koopmans
    New Member
    November 13, 2017

    The 98% bug has been solved in the Forticlient 5.6.x release (new VPN driver)

    TechnoJock
    New Member
    November 21, 2017

    I am using version 5.6.2.1117 and am receiving the 98% error.

    I ran the diagnostic tool and have this from the FCDiagData\VPN folder in the generated .cab file (this seems to be the most useful of the files):

     

    Information VPN FortiSslvpn: 11156: fortissl_connect: device=ftvnic Error VPN FortiSslvpn: 4652: error: ssl_connect Error VPN FortiSslvpn: 4652: tunnel_to_fgt error Error VPN FortiSslvpn: 220: error: ras_loop(), waitResult=1. Information VPN Unable to establish the VPN connection.(E=98,T-981066010,M99,R10)

     

    I've tried some of the suggested items - disable ipv6, virtualbox connectors - worked one time but never after the first time - even with reboot/shutdown-reboot/enable-disable these connectors/yadda-yadda-yadda...

     

    Any/all suggestions are greatly appreciated.

    scerazy
    Visitor III
    November 22, 2017

    Solution in post #65 works perfectly fine.

    Why not do it & stop moaning?

    yurimj
    New Member
    December 14, 2018

    Solved! Solved! Solved!

     

    I have discovered what is happening!!!

     

    When we install FortiClient again, it creates a new ISDN Channel, but it doesn't check this new ISDN Channel.

    So we should to check it.

    See: