Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ivanpop
New Contributor

Cannot connect using FortiClient VPN

Hello,

I'm using Debian 11 and I'm trying to connect to our VPN. The client status becomes: "connecting", but after a couple of seconds it just stops trying to connect.

I've already set-up my connection on a Windows PC and on and Android phone and it's working fine.

I paste the sslvpn.log where I just replaced the profile name and my IP addresses.

Spoiler
20230920 23:45:00.906 [sslvpn:INFO] main:1651 Init
20230920 23:45:00.906 [sslvpn:INFO] main:536 Load profile: "company-name"
20230920 23:45:00.907 [sslvpn:DEBG] main:545 Inherit local DNS: No
20230920 23:45:00.907 [sslvpn:DEBG] main:558 DNS service resetting interval: 0
20230920 23:45:00.907 [sslvpn:INFO] main:276 Get DBUS session bus address
20230920 23:45:00.910 [sslvpn:DEBG] main:340 get passwd: true, get cert passwd: false, get user input: false
20230920 23:45:00.919 [sslvpn:INFO] main:276 Get DBUS session bus address
20230920 23:45:00.921 [sslvpn:INFO] main:1133 Load profile: "company-name"
20230920 23:45:00.921 [sslvpn:DEBG] main:1521 FCT UID: 0D70A9C9EEBA46018F87633CA0732F28
20230920 23:45:00.922 [sslvpn:DEBG] main:1528 EMS not registed
20230920 23:45:00.922 [sslvpn:DEBG] main:1539 Public IP: "my.ip"
20230920 23:45:00.922 [sslvpn:INFO] main:1326 State: Connecting
20230920 23:45:00.975 [sslvpn:DEBG] vpn_connection:1146 Server URL: https://"VPN-Server-Ip":9443
20230920 23:45:00.982 [sslvpn:INFO] main:1326 State: Logging in
20230920 23:45:00.982 [sslvpn:INFO] vpn_connection:1530 /remote/info
20230920 23:45:01.025 [sslvpn:DEBG] vpn_connection:512 http connection closed.
20230920 23:45:01.025 [sslvpn:DEBG] vpn_connection:394 Response line: 200 OK
20230920 23:45:01.025 [sslvpn:INFO] sslvpn:76 ApiEncMethod: 0
20230920 23:45:01.025 [sslvpn:INFO] sslvpn:78 ApiRemoteAuthTimeout: 60
20230920 23:45:01.025 [sslvpn:INFO] sslvpn:80 ApiServerSalt: 4101e8fe
20230920 23:45:01.025 [sslvpn:INFO] sslvpn:81 flag: 7391
20230920 23:45:01.025 [sslvpn:INFO] vpn_connection:1530 /remote/login
20230920 23:45:01.069 [sslvpn:DEBG] vpn_connection:512 http connection closed.
20230920 23:45:01.070 [sslvpn:DEBG] vpn_connection:394 Response line: 200 OK
20230920 23:45:01.070 [sslvpn:INFO] vpn_connection:1530 /remote/logincheck
20230920 23:45:01.119 [sslvpn:DEBG] vpn_connection:512 http connection closed.
20230920 23:45:01.119 [sslvpn:DEBG] vpn_connection:394 Response line: 200 OK
20230920 23:45:01.119 [sslvpn:INFO] sslvpn:336 Authentication passed
20230920 23:45:01.119 [sslvpn:INFO] vpn_connection:1530 /remote/fortisslvpn
20230920 23:45:01.164 [sslvpn:DEBG] vpn_connection:512 http connection closed.
20230920 23:45:01.164 [sslvpn:DEBG] vpn_connection:394 Response line: 200 OK
20230920 23:45:01.164 [sslvpn:INFO] vpn_connection:1530 /remote/fortisslvpn_xml
20230920 23:45:01.225 [sslvpn:DEBG] vpn_connection:512 http connection closed.
20230920 23:45:01.225 [sslvpn:DEBG] vpn_connection:394 Response line: 200 OK
20230920 23:45:01.226 [sslvpn:DEBG] vpn_connection:1081 Login process end on status: 0
20230920 23:45:01.226 [sslvpn:INFO] sslvpn:759 Login successful
20230920 23:45:01.254 [sslvpn:INFO] main:1326 State: Configuring tunnel
20230920 23:45:01.295 [sslvpn:DEBG] vpn_connection:1695 FCT UID added: 0D70A9C9EEBA46018F87633CA0732F28
20230920 23:45:01.299 [sslvpn:DEBG] dns:259 Default route device name: nm-bridge
20230920 23:45:01.315 [sslvpn:DEBG] dns:207 Get connection name: Bridge connection 1
20230920 23:45:01.315 [sslvpn:DEBG] dns:271 DNS backup
20230920 23:45:01.333 [sslvpn:DEBG] dns:207 Get auto DNS setting: no
20230920 23:45:01.350 [sslvpn:DEBG] dns:207 Get static DNS: --
20230920 23:45:01.365 [sslvpn:DEBG] dns:207 Get system DNS search domain: --
20230920 23:45:01.381 [sslvpn:DEBG] dns:207 Get current DNS: 192.168.100.1
20230920 23:45:01.381 [sslvpn:DEBG] dns:316 Device name: nm-bridge
20230920 23:45:01.381 [sslvpn:DEBG] dns:317 Connection name: Bridge connection 1
20230920 23:45:01.381 [sslvpn:DEBG] dns:318 Ignor auto DNS: no
20230920 23:45:01.381 [sslvpn:DEBG] dns:319 DNS list: 
20230920 23:45:01.381 [sslvpn:DEBG] dns:320 DNS search domain list: 
20230920 23:45:01.381 [sslvpn:DEBG] dns:321 Current DNS list: 192.168.100.1
20230920 23:45:01.381 [sslvpn:DEBG] dns:322 VPN device name: vpn0036759494
20230920 23:45:01.381 [sslvpn:DEBG] dns:326 Save backup file
20230920 23:45:01.385 [sslvpn:DEBG] dns:986 Config DNS
20230920 23:45:01.388 [sslvpn:DEBG] dns:663 Device name: nm-bridge
20230920 23:45:01.388 [sslvpn:DEBG] dns:667 Connection name: Bridge connection 1
20230920 23:45:01.388 [sslvpn:DEBG] dns:671 VPN device name: vpn0036759494
20230920 23:45:01.388 [sslvpn:DEBG] dns:681 Add DNS server: 10.50.30.3
20230920 23:45:01.388 [sslvpn:DEBG] dns:681 Add DNS server: 10.50.30.4
20230920 23:45:01.388 [sslvpn:DEBG] dns:694 Setup default interface
20230920 23:45:01.388 [sslvpn:DEBG] dns:700 Disable DHCP auto DNS
20230920 23:45:01.408 [sslvpn:DEBG] dns:730 Set DNS server: 10.50.30.3 10.50.30.4 
20230920 23:45:01.427 [sslvpn:DEBG] dns:760 Set DNS domain: 
20230920 23:45:01.447 [sslvpn:DEBG] dns:790 NM reapply
20230920 23:45:01.463 [sslvpn:DEBG] dns:821 Setup VPN interface
20230920 23:45:01.463 [sslvpn:DEBG] dns:823 Set DNS server: 10.50.30.3 10.50.30.4 
20230920 23:45:01.527 [sslvpn:DEBG] dns:853 Set DNS domain: 
20230920 23:45:01.578 [sslvpn:DEBG] dns:883 NM reapply
20230920 23:45:01.592 [sslvpn:DEBG] dns:898 Apply settings failed, try again after 1 sec
20230920 23:45:02.606 [sslvpn:DEBG] dns:898 Apply settings failed, try again after 1 sec
20230920 23:45:03.620 [sslvpn:DEBG] dns:898 Apply settings failed, try again after 1 sec
20230920 23:45:04.629 [sslvpn:DEBG] dns:151 Restart DNS service failed.
20230920 23:45:04.631 [sslvpn:DEBG] dns:161 Flush DNS cache failed.
20230920 23:45:04.631 [sslvpn:DEBG] route:99 route backup START
20230920 23:45:04.631 [sslvpn:DEBG] route:151 route backup DONE
20230920 23:45:04.631 [sslvpn:DEBG] route:237 begin route config
20230920 23:45:04.631 [sslvpn:DEBG] route:238 Remote IP: "VPN-Server-Ip"
20230920 23:45:04.631 [sslvpn:DEBG] route:239 Local IP: 172.31.254.3
20230920 23:45:04.631 [sslvpn:DEBG] route:240 Tunnel mode: Split tunnel
20230920 23:45:04.631 [sslvpn:DEBG] route:241 Exclusive routing: Disabled
20230920 23:45:04.631 [sslvpn:DEBG] route:299 Can't find dev for IP 172.31.254.3 (tun)
20230920 23:45:04.631 [sslvpn:EROR] vpn_connection:1303 Config routing table failed
20230920 23:45:04.686 [sslvpn:DEBG] dns:364 Restore DNS config
20230920 23:45:04.686 [sslvpn:DEBG] dns:421 Device name: nm-bridge
20230920 23:45:04.686 [sslvpn:DEBG] dns:422 Connection name: Bridge connection 1
20230920 23:45:04.686 [sslvpn:DEBG] dns:423 Ignor auto DNS: no
20230920 23:45:04.686 [sslvpn:DEBG] dns:424 DNS list: 
20230920 23:45:04.687 [sslvpn:DEBG] dns:425 DNS search domain list: 
20230920 23:45:04.687 [sslvpn:DEBG] dns:426 VPN device name: vpn0036759494
20230920 23:45:04.850 [sslvpn:DEBG] route:159 begin cleanup linux...
20230920 23:45:04.850 [sslvpn:DEBG] route:161 clean up route...
20230920 23:45:04.850 [sslvpn:DEBG] main:1697 exception: Config routing table failed
20230920 23:45:08.059 [sslvpn:INFO] main:1651 Init
20230920 23:45:08.059 [sslvpn:INFO] main:1707 VPN is running in restore DNS mode
20230920 23:45:08.063 [sslvpn:DEBG] dns:364 Restore DNS config
20230920 23:45:08.063 [sslvpn:DEBG] dns:416 No backup file was found. Skip.

I also have a bridged connection called nm-bridge, with my Ethernet connection as a slave, since I have VM's which are connected using Bridged network.

4 REPLIES 4
nageentaj
Staff
Staff

Hi Team,

 

Let us know if you followed the steps below for installing forticlient vpn on Debian 11.
If you would like to install it on your Debian machine, you can try to download the .deb file from fortinet.com/support/product-downloads#vpn and use dpkg -i <file name> to install.


Kindly refer to https://docs.fortinet.com/document/forticlient/7.0.2/administration-guide/269675/feature-comparison-...


Please check the document below with the instructions to install the Forticlient VPN on Debian (using the installation file or Repo):

https://docs.fortinet.com/document/forticlient/7.0.7/administration-guide/437544/installing-forticli...
https://docs.fortinet.com/document/forticlient/7.0.7/administration-guide/213138/installing-forticli...


For the free version, you need to download the installer from the website: https://www.fortinet.com/support/product-downloads#vpn. Please follow the steps below:

1. Install the below dependencies:

sudo apt install libappindicator1
sudo apt install libgconf-2-4

2.- Install the .deb on downloaded directory

sudo dpkg -i packet_name

3.- Optional, in case an error is shown on the output, you can use the option fix broken install

sudo apt --fix-broken install

Please try these steps and comment on the results.

ivanpop

Hello,

I tried these steps and is exactly the same. Not connecting

spoojary
Staff
Staff

Change the version of the FCT you are using and you should be good. If possible get to 6.4.9 or 10 to check the compatibility issue.

Siddhanth Poojary
ivanpop

I managed to download 6.4.8 using the method described in here:

https://www.fortinet.com/support/product-downloads/linux

 

I used the Forticlient 6.4 and the settings for Ubuntu 18.04 LTS and 20.04 LTS

The client is definitely different, but it still wont' connect. It also states that is UNLICENSED and I have one month of available access.

This is sslvpn.log:

Spoiler
20230921 21:52:43.652 [sslvpn:INFO] main:1650 Init
20230921 21:52:43.653 [sslvpn:INFO] main:536 Load profile: mr
20230921 21:52:43.653 [sslvpn:INFO] main:276 Get DBUS session bus address
20230921 21:52:43.664 [sslvpn:INFO] main:276 Get DBUS session bus address
20230921 21:52:43.666 [sslvpn:INFO] main:1132 Load profile: mr
20230921 21:52:43.667 [sslvpn:INFO] main:1325 State: Connecting
20230921 21:52:43.720 [sslvpn:INFO] main:1325 State: Logging in
20230921 21:52:43.720 [sslvpn:INFO] vpn_connection:1510 /remote/info
20230921 21:52:43.765 [sslvpn:INFO] sslvpn:76 ApiEncMethod: 0
20230921 21:52:43.765 [sslvpn:INFO] sslvpn:78 ApiRemoteAuthTimeout: 60
20230921 21:52:43.765 [sslvpn:INFO] sslvpn:80 ApiServerSalt: 4101e8fe
20230921 21:52:43.765 [sslvpn:INFO] sslvpn:81 flag: 7391
20230921 21:52:43.765 [sslvpn:INFO] vpn_connection:1510 /remote/login
20230921 21:52:43.809 [sslvpn:INFO] vpn_connection:1510 /remote/logincheck
20230921 21:52:43.858 [sslvpn:INFO] sslvpn:336 Authentication passed
20230921 21:52:43.858 [sslvpn:INFO] vpn_connection:1510 /remote/fortisslvpn
20230921 21:52:43.904 [sslvpn:INFO] vpn_connection:1510 /remote/fortisslvpn_xml
20230921 21:52:43.963 [sslvpn:INFO] sslvpn:759 Login successful
20230921 21:52:44.031 [sslvpn:INFO] main:1325 State: Configuring tunnel
20230921 21:52:44.315 [sslvpn:EROR] vpn_connection:1283 Config routing table failed
20230921 21:52:50.019 [sslvpn:INFO] main:1650 Init
20230921 21:52:50.019 [sslvpn:INFO] main:1706 VPN is running in restore DNS mode

And it also changes my nameserver inside /etc/resolv.conf with the ones stated on my VPN server, which kills my internet connection. I have to remove them and insert my router's IP in order to fix my connection.

Top Kudoed Authors