FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
hbac
Staff
Staff
Article Id 248363
Description

This article describes how to solve an issue when users are not able to connect to the SSL VPN using FortiClient. When trying to connect, it is stuck at 98%. 

Scope FortiClient.
Solution

hbac_0-1678291291276.png

 

- SSL VPN debugs on the FortiGate do not show any errors.

 

- FortiClient logs showed the following errors:

 

user=test@fortinet msg="SSLVPN tunnel connection failed" vpnstate= vpntunnel=fortinet vpnuser=test remotegw=vpn.fortinet.com

2/23/2023 11:22:36 AM         info      sslvpn  FortiSslvpn: 13576: fortissl_connect: device=ftvnic

2/23/2023 11:22:36 AM         error    sslvpn  FortiSslvpn: 15344: RasGetEntryPropertiesWin7(fortissl) failed. (r=623)

2/23/2023 11:22:36 AM         error    sslvpn  FortiSslvpn: 15344: error: ssl_connect:-3

2/23/2023 11:22:36 AM         error    sslvpn  FortiSslvpn: 15344: tunnel_to_fgt error

2/23/2023 11:22:38 AM         error    sslvpn  FortiSslvpn: 14544: error: ras_loop(), waitResult=1.

 

This issue usually occurs due to IPv6 being enabled on the NIC of the client machine.

 

It can be resolved by disabling IPv6 on the NIC of the client machine.

Comments
Umer221
Staff
Staff

Thank you for writing this article. It is helpful resolving issues where IPv6 is enabled specifically on Windows 11 host.

Contributors