| Description | This article describes how to troubleshoot an issue where SSL connection fails in FIPS-MODE due to the error 'encoding method rejected in fips-cc mode'. |
| Scope |
FortiGate and FortiClient. |
| Solution |
When FortiGate is running in FIPS Mode, SSL connection may not establish when using a tunnel mode FortiClient connection.
In the SSL VPN debug logs, the following output is seen.
diag debug disable diag debug application sslvpn -1 diad debug enable
mt_web_auth_info_parser_common:533 no session id in auth info
When the connection is tested with web mode, it works as expected.
The issue is with the FortiClient version which is not compatible with the FIPS configuration on firewall.
FortiClient version 7.2.5, 7.4.1, or higher should be used with FortiGate with FIPS enabled. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.