FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Umer221
Staff
Staff
Article Id 291484
Description This article provides a solution to an issue where RDP between Windows 11 PC connected via IPsec Dial-up fails while the rest of the services such as ping work fine. Issue is not observed between the devices running on older versions of Windows.
Scope Windows 11, FortiOS, FortiGate, IPsec Dial-up.
Solution

The following error appears during an RDP attempt:

 

MicrosoftTeams-image (121).png

 

Navigate to 'Log & Report -> Forward Traffic', and filter for the traffic specific to RDP. Here, the following error will appear: Policy Action - Accept: session timeout.

 

  1. First, make sure that IPsec dial-up is configured properly by following the instructions in: Technical Tip: IPSec dial-up full tunnel with FortiClient.

  2. If all the above configuration matches, then test if the rest of the services such as ping are working fine except for RDP between the devices running on Windows 11.

  3. Verify if RDP is working fine between the devices running on older versions of Windows, such as Windows 10, Windows 8, or Windows 7.

  4. If all of the above symptoms match, go to the policy that is created for IPsec dial-up connection according to the article mentioned in step 1, and disable NAT for that policy. This should resolve issues for RDP between Windows 11 devices.

 

kb_17882_11.png