Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
17g
New Contributor

Forticlient 6.2 - Enable VPN before logon - Missing

Hi Guys

 

I recently upgraded my Fortigate to Firmware 6.2. The first thing I noticed was that my older 6.0.4 Forticlient version would no longer connect using its IPSEC VPN profile. After a call with Fortinet support they concluded that only new Forticlient version 6.2 would work with FG 6.2 This indeed does seem to be the case.

 

This gets me to my current issue: The “Enable VPN before logon” option has been removed from 6.2. This setting is a major ‘bread and butter’ setting enabling remote users to do proper domain logins from remote and apply Group Polices etc. I raised this with Fortinet support who confirmed the feature had been removed:

 

I would like to mention that starting with FCT 6.2.0 many things has changed, Free Forticlient 6.2.0 comes up with basic and limited VPN functionality and if you want to use full functionality of 6.2.0, EMS licenses has to be procured.  Please refer below FCT compatibility guide for your reference .  https://fortinetweb.s3.am...bility-chart.pdf 

 

and that was final and to get in contact with Fortinet Sales

 

Note: I use the free license for Forticlient just needing to use VPN functionality.

 

I have been desperately been trying to figure out alternatives such as:

L2TP Windows native – This works with enable before logon but has limitations as well as FG authentication issues meaning users don’t get authenticated to IPv4 polices – Ongoing ticket with Fortinet support

A 3rd Party VPN client connecting to FG via SSL VPN – I thought I could get OpenVPN client connecting but this doesn’t appear to work

 

I have now gone full circle and re-investigating the Forticlient. I noticed when backing up the config and opening with notepad++ there is an option <show_vpn_before_logon>. If I change this to “1” and then import the config, this doesn’t appear to take any effect on the Forticlient/Windows shell config.

 

It appears Fortinet have done everything in their power to make the free version useless.

 

Am I flogging a dead horse? I just can’t believe removing this Windows logon feature wouldn’t cause a major backlash from Forticlient customer base? If I have no alternative than to spend more money, what is the minimum product/license I need to purchase?

7 REPLIES 7
michael_proctor
New Contributor

I am curious where this ends up, in the same boat.

17g

FYI - Ended up forking out for EMS. No choice unfortunately. 

blloyd1
New Contributor

I recently had a request from a user to login to VPN before windows login.

FG ver is 5.6.3 GA  and we use the 6.2.x client ( yes bad practice , incompatible versions ).

As you would guess , the option is removed from the UI in the 6.2 version.

 

On a whim and suggestion from another user using the 5.6.6 Forticlient version who saw the option listed in the settings , I uninstalled the 6.2.x client and re-installed the 5.6.6 client.

 

Logon to VPN before windows login   Works !

 

Not sure if 5.6.6 client is incompatible with future FG versions, but for this situation it does work.

 

jpcastilloux

In the same boat too here !

 

I discovered that the Before Logon problem appears at version 6.0.10 precisely.

If you install 6.0.9, it's still working.

 

But seriously Fortinet ... are you really removing this basic feature ? You will lose a lot of customer by doing that because we are clearly not gonna buy licenses only for this feature, we will focus on choosing a VPN Concentrator to resolve this instead of buying your FortiEMS licenses when we dont need that much.

 

Fortinet equipments are cheap and today we are starting to know why. Once they have a good portion of the market, now they are beginning to force us to pay license for basics functions.

 

Sad....

Counterdoc
New Contributor

We experienced the same issue and are using the older versions for now...

marshalisms

***UPDATE***

Forticlient runs as a credential provider when you enable VPN before logon.  We installed DUO security for MFA for administrator accounts and this disabled additional credential providers.  I was able to whitelist the FortiClient credential provider with DUO in the registry and this restored the ability to logon to VPN before windows logon!  If anyone else needs this info, here you go:

Can I enable other credential providers after installing Duo Authentication for Windows Logon?

FortiClient GUID: {AC7DD106-EAB6-4b41-AC4F-D52FD62A82C7}

 

 

 

I have a weird issue with Login to VPN before Windows.  About 1-2 months ago after some windows patches, we no longer see the "Sign-in Options" on the windows signin screen.  I verified the version of Forticlient did not change, that enable VPN before login is enabled in Forticlient, and also tried the latest version with EMS.  Still no go.

 

We are in a domain environment, so it is very important for us to be able to login to VPN and windows at the same time.  Does anyone have any recommendations?

mc625569

Same issue.  Rolled back client.