This article describes how to troubleshoot why updating to Windows 11 can cause the VPN traffic to fail.
FortiGate v6.4.10, FortiClient v7.0.1.0083.
Usually, the behavior is that the VPN is working correctly on Windows 10 or earlier, but when Windows 11 is used, the connection is successful but 0 KB is received.
Consider checking the VPN SSL logs on FortiGate and this message will appear:
'Cannot determine ethernet address for proxy ARP',
Open a CMD window and run 'ipconfig /all', and verify if the correct IP is seen. If an APIPA address (169.254.x.x) is seen, that PC is likely hitting an issue regarding a specific Windows Update on Windows 11.
Run the following command in PowerShell to see if KB2693643 is installed:
Get-Hotfix KB2693643
If there is no error seen, then this Windows Update is installed. Uninstall that update, restart the PC, then try again.
After that, the connection will be successful and the traffic will flow through the VPN connection.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.