| Description | This article describes that when FortiClient is configured to connect in aggressive mode, IPsec with multiple matching Diffie-Hellman (DH) groups selected, the following error is seen on the FortiClient and FortiGate logs, even though the configuration matches on both ends. |
| Scope | FortiClient v7.2, v7.4 and v7.6. |
| Solution |
On FortiClient, the following error message is observed in the exported logs and on the notification bar: 'FortiClient Logs: utmaction=passthrough utmevent=vpn threat=disconnects Notification Windows Bar: Timeout while connecting to X.X.X.X'.
On the FortiGate, debug settings vary depending on the firmware version.
diagnose debug disable diagnose debug reset diagnose debug app ike -1 diagnose debug console timestamp enable diagnose debug enable
ike 1:13624: SA proposal chosen, matched gateway Dialup01
diagnose debug disable<----- Use this command to stop the debug.
Root Cause: The order in which DH group was selected on the FortiGate caused this error.
config vpn ipsec phase1-interface
On the FortiClient side, 14 is first in order.
Solution: Option 1: edit the VPN using CLI on the FortiGate and change the order:
Option 2: Choose only one DH GROUP on the FortiClient side: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.