| Description | This article describes how to troubleshoot and fix an IPSec VPN connection issue, which is caused by the Windows svchost.exe - IKEEXT service occupying port 4500. |
| Scope | FortiClient. |
| Solution |
FortiClient stuck at connecting status, when checking the ports 500 and 4500, notice it is being used by svchost.exe IKEEXT service as shown below:
The most effective and common solution is to disable the Windows IPSec service, which frees up the ports for the VPN client, and turn it back on later if needed.
Note: Changing the default IPsec port on both FortiClient and FortiGate can be another workaround for this issue. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.