Description |
This article describes what could be the cause if the FortiClient VPN fails to connect at 40% with PKI certificate authentication. |
Scope | FortiClient SSL VPN with PKI certificate authentication. |
Solution |
The logs will show the Action as 'ssl-exit-error' and the Reason as 'DH lib'.
SSL-VPN application real time debug will show the following:
client cert requirement: yes
Uninstall and reinstall the client certificate.
Note: In this instance the client certificate is not expired. It just needs to be reinstalled.
Troubleshooting:
diagnose debug reset diagnose vpn ssl
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.