Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kssupport
New Contributor

help - forticlient Failed establish vpn connection - mismatch TLS VERSION

hi there,

 

need help. we use FORTIGATE 60D, with firmware 5.6.12

one of users suddenly fail to connect over vpn ssl.

error message: failed to establish the vpn connection. this may be caused by a mismatch in the tls version.

 

we've ticked all tls version in internet option.

user use windows 10 pro.

os build 19043.1348

 

this computer had no issue before. but somehow just got an issue now.

another computer use windows 10 has no problem at all for connect vpn ssl connection

 

anyone have experience same issue?

need help please.

thank you

 

1 REPLY 1
Markus_M
Staff
Staff

TLS version mismatch would indicate exactly that. TLS will be an encrypted tunnel over which the payload is transported.

The tunnel has to be build between two nodes and one will propose a set of ciphers according to its capabilities and it will conform the TLS version. If the server does not speak the same version, they cannot agree on a used cipher - that error is thrown. The Windows 10 device or the FortiClient could enforce certain TLS cipher suites that the FortiGate does not support.

 

Seeing the FortiGate Firmware version, you might consider upgrading it; the latest firmware for that FortiGate is 6.0.14.

To technically see what the client is sending, you can use wireshark on the client and filter for the FortiGate IP address and follow communication on the SSLVPN port you have configured.

That can be compared between both clients.

Labels
Top Kudoed Authors