FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
SAJUDIYA
Staff
Staff
Article Id 352961
Description

This article describes an error, 'Unable to establish VPN connection. The VPN server may be unreachable (-6005)' at 40% in FortiClient.

 

However, the error 'wrong vdom (0:0) or time expired' appears in SSL VPN debug.

Scope

FortiGate.

Solution
  1. Run the SSL VPN debug as below and see the error below:

diagnose debug application sslvpnd -1

diagnose debug enable

 

To stop the debugs:

 

diagnose debug disable

diagnose debug reset


2024-01-11 10:00:53 [1654:root:70d]req: /remote/saml/login
2024-01-11 10:00:53 [1654:root:70d]Transfer-Encoding n/a
2024-01-11 10:00:53 [1654:root:70d]Content-Length 9059
2024-01-11 10:00:53 [1654:root:70d]readPostEnter:17 Post Data length 9059.
2024-01-11 10:00:53 [1654:root:70d]fsv_rmt_saml_login_cb:91 SAML resp 8908.
2024-01-11 10:00:53 [1654:root:70d]fsv_rmt_saml_login_cb:121 wrong vdom (0:0) or time expired.
2024-01-11 10:00:53 [1654:root:70d]Destroy sconn 0x7f9bee8800, connSize=2. (root)

2024-01-11 10:00:53 [1654:root:70d]SSL state:warning close notify (1.192.64.53)

 

  1. Increase the remoteauthtimeout value as below:

    config system global

        set remoteauthtimeout 60

    end

 

  1. If the issue persists, it is necessary to sync the local machine time with FortiGate time, and it should work.

  2. If that does not work, restart the SSL VPN and upgrade to FortiClient v7.2.4 or above.

 

Note:

Starting from v7.6.3, the SSL VPN tunnel mode feature is not supported, and it is replaced with IPSEC VPN: SSL VPN tunnel mode replaced with IPsec VPN

 

Related articles:

Troubleshooting Tip: Companion for troubleshooting SSL VPN with SAML Authentication

Troubleshooting Tip: Cannot login to VPN after accepting MFA with the SAML SSO on Azure Entra debug ...