FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
knaveenkumar
Staff
Staff
Article Id 267856
Description This article describes how to resolve the SSL VPN not connecting issue.
Scope SSL VPN not connecting and getting the error like 'credential or SSL VPN configuration is wrong.' (-7200).
Solution

The user is not able to connect to the SSL VPN and the error 'credential or SSL VPN configuration is wrong.' (-7200). is seen.

 

ssl....e.PNGIn order to see what is going wrong with the SSL VPN, take the following debug:


di de res
di de app sslvpn -1

di de app fnbamd -1
di de en

 

Here is the output after a failed connection attempt:

 

fnbamd.PNG

 

It is seen that the FortiGate is configured with an LDAP server and that the user is a part of two groups: 'example_group' and 'Domain Users'. When checking the configured LDAP group in the policy, the AD group information is missing.

 

new.PNG

 

Here is the configuration after an AD group is added:

 

ldap.PNG

Once applied, the user will be able to connect to the SSL VPN successfully.

 

ssl connected.PNG