Created on
06-16-2023
02:42 AM
Edited on
06-24-2025
11:15 PM
By
Jean-Philippe_P
Description | This article describes how to solve the error 'Credential or SSLVPN configuration is wrong. (-7200)' that occurs during an SSL VPN login. |
Scope | FortiGate 7.0. |
Solution |
The error in the GUI:
date=2023-06-16 time=17:46:09 eventtime=1686905169441057904 tz="+0900" logid="0101039425" type="event" subtype="vpn" level="information" vd="root" logdesc="SSL VPN tunnel down" action="tunnel-down" tunneltype="ssl-web" tunnelid=19067030 remip=10.200.20.10 user="guest" group="N/A" dst_host="N/A" reason="tunnel connection setup timeout" duration=32 sentbyte=0 rcvdbyte=0 msg="SSL tunnel shutdown" action="ssl-exit-error" tunneltype="ssl" tunnelid=0 remip=10.200.20.10 srccountry="Reserved" user="N/A" group="N/A" dst_host="N/A" fctuid="N/A" reason="N/A" msg="SSL exit error"
In the CLI:
diagnose debug application sslvpn -1 [2612:root:1b]deconstruct_session_id:716 decode session id ok, user=[guest], group=[],authserver=[],portal=[full-access],host[10.200.20.10],realm=[],csrf_token=[D3D4129C5AB9CB25CDCE01CCF8E40],idx=0,auth=1, sid=2d772154, login=1686904099,access=1686904099,saml_logout_url=no,pip=no,grp_info=[4xAcoJ], rmt_grp_info=[]
This may occur due to several reasons:
To fix the second case, reduce the security level from 'High' to 'Medium-high' or 'Medium'.
Note:
Related documents: Technical Tip: Unable to establish the SSL VPN connection on Windows server |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.