FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
bkarl
Staff
Staff
Article Id 251666
Description

 

This article describes how to troubleshoot the VPN fail route from PC Client which it has Windows 11 installed with FortiClient.

 

Scope

 

FortiGate v6.4.10, FortiClient v7.0.1.0083.

 

Solution

 

Usually, the behavior is that the VPN is working correctly on Windows 10 or earlier, but when  Windows 11 is used, the connection is successful but 0 KB is received.

 

Consider checking the VPN SSL logs on FortiGate and  this message will appear:

'Cannot determine ethernet address for proxy ARP',

 

KB10 - 1.jpg

 

Open a CMD window and a different IP address like 169.254.146.223 or something similar instead the IP pool is configured as below.

 

KB10 - 2.png

 

If the remote services are pinged, the ping will not work:

 

KB10 - 3.png

 

Uninstall Windows Update: KB2693643 and restart the system.

After that, the connection will be successful and the traffic will flow through the VPN connection.

Contributors