FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
mithing
Staff
Staff
Article Id 360812
Description This article describes what to do when a VPN fails to connect with the error 'VPN blocked, please contact IT administrator' display.
Scope FortiClient 7.2.x and EMS 7.2.x.
Solution

The FortiClient VPN getting this message because the EMS has enabled the features to block 'Configuring a profile to allow or block endpoint from VPN tunnel connection based on the applied security posture tag' under the remote access endpoint profile.

 

More details available there:
Configuring a profile to allow or block endpoint from VPN tunnel connection based on the applied Zer...

 

Sample message:

 

sample1.PNG

 

This message is the default message, however, it can be customized, for example:

 

sample2.PNG

 

To resolve this:

Ensure the endpoint device matches and satisfies (depending on the criteria tag that the EMS administrator chooses)  the tagging that is assigned under the VPN profile.

 

sample3.PNG

 

The criteria rule can be checked under the zero trust tag.

 

sample4.PNG

 

This check is executed only if the option 'Enable Secure Remote Access' is enabled on the Remote Access profile.

 

2024-11-29 14_25_09-FortiClient Cloud.png