FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
bkarl
Staff
Staff
Article Id 251666
Description

 

This article describes how to troubleshoot why updating to Windows 11 can cause the VPN traffic to fail.

 

Scope

 

FortiGate v6.4.10, FortiClient v7.0.1.0083.

 

Solution

 

Usually, the behavior is that the VPN is working correctly on Windows 10 or earlier, but when  Windows 11 is used, the connection is successful but 0 KB is received.

 

Consider checking the VPN SSL logs on FortiGate and  this message will appear:

'Cannot determine ethernet address for proxy ARP',

 

KB10 - 1.jpg

 

Open a CMD window and run 'ipconfig /all', and verify if the correct IP is seen. If an APIPA address (169.254.x.x) is seen,  that PC is likely hitting an issue regarding a specific Windows Update on Windows 11.

 

KB10 - 2.png

 

Run the following command in PowerShell to see if KB2693643 is installed:


Get-Hotfix KB2693643

 

If there is no error seen, then this Windows Update is installed. Uninstall that update, restart the PC, then try again.

After that, the connection will be successful and the traffic will flow through the VPN connection.