| Description | This article describes an issue with L2TP VPN connection from Windows native client to FortiGate. |
| Scope | FortiGate. |
| Solution |
When trying to connect from a Windows VPN, it shows the following error.
Debug commands on FortiGate show the following outputs with 'Out of IP addresses on tunnel' message.
diagnose debug application ike -1 diagnose debug application l2tp -1 diagnose debug enable
run_ctrl_state_machine()-74: run_ctrl_state_machine: message type is (10). Tunnel is 1, call is 1.
This issue happens because of address range misconfiguration. In this example, there is no available IP address because start IP and end IP are the same as shown below.
show vpn l2tp
To resolve the issue, configure the start IP and end IP correctly to make sure there are enough IP addresses to be assigned to L2TP VPN clients.
config vpn l2tp
After correcting the IP address range, the user is able to connect.
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.