Description |
This article describes when users are using web base VPN and can connect to the VPN, but through FortiClient they are facing issues. |
Scope | |
Solution |
1) Take the debug for the VPN user by below command:
# diagnose debug application sslvpn -1 # diagnose debug flow filter addr x.x.x.x <----- User public IP. # diagnose debug enable
2) If the compatibility is not there, the below error in the debug will appear:
[2535:root:35b]client sent request without hostname (see RFC2616 section 14.23): /. [2535:root:35b]sslConnGotoNextState:297 error (last state: 1, closeOp: 0) [2535:root:35b]Destroy sconn 0x311ab100, connSize=1. (root)
Between FortiGate and FortiClient compatibility has to be there, if it is not a logout post will appear while connecting to VPN.
It is possible to check the compatibility by using the below link
Now use the proper client version and check the connection, if the issue is still there create a ticket through the Fortinet support portal. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.