Description |
This article describes when users are using web base VPN and can connect to the VPN, but through FortiClient they are facing issues. |
Scope | FortiGate. |
Solution |
diagnose debug application sslvpn -1 diagnose debug flow filter addr x.x.x.x <----- User public IP. diagnose debug enable
[2535:root:35b]client sent request without hostname (see RFC2616 section 14.23): /. [2535:root:35b]sslConnGotoNextState:297 error (last state: 1, closeOp: 0) [2535:root:35b]Destroy sconn 0x311ab100, connSize=1. (root)
Between FortiGate and FortiClient compatibility has to be there, if it is not a logout post will appear while connecting to the VPN.
It is possible to check the compatibility by using the below link forticlient_ems-compatibility-matrix.pdf (fortinetweb.s3.amazonaws.com)
Use the proper client version and check the connection, if the issue is still there create a ticket through the Fortinet support portal. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.