Am using FortiClient VPN 7.0.0.0018 on Fedora 36, the same settings are working fine on Windows 10
20221008 06:45:54.296 [sslvpn:INFO] main:1412 Init
20221008 06:45:54.296 [sslvpn:INFO] main:370 Load profile: dhims
20221008 06:45:54.297 [sslvpn:INFO] main:118 Get DBUS session bus address
20221008 06:45:54.317 [sslvpn:INFO] main:118 Get DBUS session bus address
20221008 06:45:54.323 [sslvpn:INFO] main:941 Load profile: dhims
20221008 06:45:54.324 [sslvpn:INFO] main:1112 State: Connecting
20221008 06:45:54.373 [sslvpn:INFO] main:1112 State: Logging in
20221008 06:45:54.373 [sslvpn:INFO] vpn_connection:1493 /remote/info
20221008 06:45:54.489 [sslvpn:INFO] main:1112 State: Waiting user confirm remote certificate
20221008 06:45:57.087 [sslvpn:INFO] main:1112 State: Logging in
20221008 06:45:57.087 [sslvpn:INFO] vpn_connection:1493 /remote/info
20221008 06:45:57.291 [sslvpn:INFO] sslvpn:76 ApiEncMethod: 0
20221008 06:45:57.292 [sslvpn:INFO] sslvpn:78 ApiRemoteAuthTimeout: 30
20221008 06:45:57.292 [sslvpn:INFO] sslvpn:80 ApiServerSalt: 19e5eba8
20221008 06:45:57.292 [sslvpn:INFO] sslvpn:81 flag: 1247
20221008 06:45:57.292 [sslvpn:INFO] vpn_connection:1493 /remote/fortisslvpn_xml
20221008 06:45:57.492 [sslvpn:INFO] sslvpn:739 Login successful
20221008 06:45:57.529 [sslvpn:INFO] main:1112 State: Configuring tunnel
20221008 06:45:58.360 [sslvpn:EROR] vpn_connection:1263 Backup routing table failed
Hello
Did you bypass some pkg dependencies when you installed FortiClient package?
Does the VPN connection establish successfully despite of this error message?
If so then please share your routing table before and after the connection.
Otherwise try reinstall but with providing all required dependencies.
Hello,
I had encountered the almost identical problem with my laptop using FortiClient VPN 7.0.0.0018 on Fedora 36. It only happened to WiFi connection.
If using LAN cable connecting to the same route, VPN can be established just fine.
The trimmed sslvpn.log is
20221017 16:31:41.245 [sslvpn:INFO] main:1412 Init
20221017 16:31:41.245 [sslvpn:INFO] main:370 Load profile: telenav
20221017 16:31:41.246 [sslvpn:INFO] main:118 Get DBUS session bus address
20221017 16:31:41.258 [sslvpn:INFO] main:118 Get DBUS session bus address
20221017 16:31:41.259 [sslvpn:INFO] main:941 Load profile: telenav
20221017 16:31:41.260 [sslvpn:INFO] main:1112 State: Connecting
20221017 16:31:41.324 [sslvpn:INFO] main:1112 State: Logging in
20221017 16:31:41.324 [sslvpn:INFO] vpn_connection:1493 /remote/info
20221017 16:31:41.537 [sslvpn:INFO] sslvpn:76 ApiEncMethod: 0
20221017 16:31:41.537 [sslvpn:INFO] sslvpn:78 ApiRemoteAuthTimeout: 120
20221017 16:31:41.537 [sslvpn:INFO] sslvpn:80 ApiServerSalt: 6793ce25
20221017 16:31:41.537 [sslvpn:INFO] sslvpn:81 flag: 223
20221017 16:31:41.537 [sslvpn:INFO] vpn_connection:1493 /remote/login
20221017 16:31:41.709 [sslvpn:INFO] vpn_connection:1493 /remote/logincheck
20221017 16:31:43.981 [sslvpn:INFO] sslvpn:215 /remote/logincheck returns 401
20221017 16:31:43.981 [sslvpn:INFO] sslvpn:224 Check response
20221017 16:31:50.848 [sslvpn:INFO] vpn_connection:1493 /remote/logincheck
20221017 16:31:51.731 [sslvpn:INFO] sslvpn:336 Authentication passed
20221017 16:31:51.731 [sslvpn:INFO] vpn_connection:1493 /remote/fortisslvpn
20221017 16:31:51.895 [sslvpn:INFO] vpn_connection:1493 /remote/fortisslvpn_xml
20221017 16:31:52.066 [sslvpn:INFO] sslvpn:739 Login successful
20221017 16:31:52.102 [sslvpn:INFO] main:1112 State: Configuring tunnel
20221017 16:31:52.514 [sslvpn:EROR] vpn_connection:1263 Backup routing table failed
The trimmed output of systemd-journald is as below:
Oct 17 16:31:33 Fortitray.desktop[8949]: Fontconfig warning: "/usr/share/fontconfig/conf.avail/05-reset-dirs-sample.conf", line 6: unknown element "reset-dirs"
Oct 17 16:31:33 Fortitray.desktop[8949]: Platform detected: fedora
Oct 17 16:31:33 Fortitray.desktop[8949]: [ '/opt/forticlient/gui/FortiClient-linux-x64/FortiClient' ]
Oct 17 16:31:33 Fortitray.desktop[8949]: did-finish-load
Oct 17 16:31:34 Fortitray.desktop[8949]: renderer ready - IPC_RENDERER_REQUEST.FETCH_INVITATION_CODE 2022-10-17T08:31:34.459Z
Oct 17 16:31:41 gnome-keyring-daemon[2153]: asked to register item /org/freedesktop/secrets/collection/login/1, but it's already registered
Oct 17 16:31:52 gnome-keyring-daemon[2153]: asked to register item /org/freedesktop/secrets/collection/login/1, but it's already registered
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1045] manager: (vpn): new Tun device (/org/freedesktop/NetworkManager/Devices/6)
Oct 17 16:31:52 systemd-udevd[9164]: Using default interface naming scheme 'v250'.
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1156] device (vpn): state change: unmanaged -> unavailable (reason 'connection-assumed', sys-iface-state: 'external')
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1161] device (vpn): state change: unavailable -> disconnected (reason 'connection-assumed', sys-iface-state: 'external')
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1167] device (vpn): Activation: starting connection 'vpn' (340ea4a5-a726-4ea4-80d2-e67ea7fc0cf7)
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1188] device (vpn): state change: disconnected -> prepare (reason 'none', sys-iface-state: 'external')
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1191] device (vpn): state change: prepare -> config (reason 'none', sys-iface-state: 'external')
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1193] device (vpn): state change: config -> ip-config (reason 'none', sys-iface-state: 'external')
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1195] device (vpn): state change: ip-config -> ip-check (reason 'none', sys-iface-state: 'external')
Oct 17 16:31:52 systemd[1]: Starting NetworkManager-dispatcher.service - Network Manager Script Dispatcher Service...
Oct 17 16:31:52 systemd[1]: Started NetworkManager-dispatcher.service - Network Manager Script Dispatcher Service.
Oct 17 16:31:52 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=NetworkManager-dispatcher comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1302] device (vpn): state change: ip-check -> secondaries (reason 'none', sys-iface-state: 'external')
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1305] device (vpn): state change: secondaries -> activated (reason 'none', sys-iface-state: 'external')
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.1308] device (vpn): Activation: successful, device activated.
Oct 17 16:31:52 systemd[1]: iscsi.service: Unit cannot be reloaded because it is inactive.
Oct 17 16:31:52 chronyd[1269]: Source 162.159.200.123 online
Oct 17 16:31:52 chronyd[1269]: Source 162.159.200.1 online
Oct 17 16:31:52 chronyd[1269]: Source 78.46.102.180 online
Oct 17 16:31:52 chronyd[1269]: Source 202.28.116.236 online
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.3430] audit: op="connection-update" uuid="6b042000-0b66-452c-a857-2dda118cd4eb" name="MyWifi" pid=9214 uid=0 result="success"
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.3610] audit: op="connection-update" uuid="6b042000-0b66-452c-a857-2dda118cd4eb" name="MyWifi" args="ipv4.dns" pid=9218 uid=0 result="success"
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.3821] audit: op="connection-update" uuid="6b042000-0b66-452c-a857-2dda118cd4eb" name="MyWifi" pid=9222 uid=0 result="success"
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.3987] audit: op="device-reapply" interface="wlp1s0" ifindex=2 args="ipv4.dns" pid=9226 uid=0 result="success"
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.4106] dhcp4 (wlp1s0): canceled DHCP transaction
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.4106] dhcp4 (wlp1s0): activation: beginning transaction (timeout in 45 seconds)
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.4106] dhcp4 (wlp1s0): state changed no lease
Oct 17 16:31:52 avahi-daemon[1214]: Withdrawing address record for fe80::6f9c:113e:1f00:5449 on wlp1s0.
Oct 17 16:31:52 avahi-daemon[1214]: Leaving mDNS multicast group on interface wlp1s0.IPv6 with address fe80::6f9c:113e:1f00:5449.
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.4121] dhcp4 (wlp1s0): activation: beginning transaction (timeout in 45 seconds)
Oct 17 16:31:52 avahi-daemon[1214]: Interface wlp1s0.IPv6 no longer relevant for mDNS.
Oct 17 16:31:52 avahi-daemon[1214]: Withdrawing address record for 192.168.199.159 on wlp1s0.
Oct 17 16:31:52 avahi-daemon[1214]: Leaving mDNS multicast group on interface wlp1s0.IPv4 with address 192.168.199.159.
Oct 17 16:31:52 systemd-resolved[7950]: wlp1s0: Bus client reset search domain list.
Oct 17 16:31:52 systemd-resolved[7950]: wlp1s0: Bus client set default route setting: no
Oct 17 16:31:52 avahi-daemon[1214]: Interface wlp1s0.IPv4 no longer relevant for mDNS.
Oct 17 16:31:52 dnsmasq[1603]: reading /etc/resolv.conf
Oct 17 16:31:52 dnsmasq[1603]: using nameserver 127.0.0.53#53
Oct 17 16:31:52 systemd-resolved[7950]: wlp1s0: Bus client reset DNS server list.
Oct 17 16:31:52 avahi-daemon[1214]: Joining mDNS multicast group on interface wlp1s0.IPv6 with address fe80::6f9c:113e:1f00:5449.
Oct 17 16:31:52 avahi-daemon[1214]: New relevant interface wlp1s0.IPv6 for mDNS.
Oct 17 16:31:52 avahi-daemon[1214]: Registering new address record for fe80::6f9c:113e:1f00:5449 on wlp1s0.*.
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.4366] audit: op="connection-update" uuid="340ea4a5-a726-4ea4-80d2-e67ea7fc0cf7" name="vpn" args="ipv4.dns" pid=9230 uid=0 result="success"
Oct 17 16:31:52 systemd-resolved[7950]: vpn: Bus client set default route setting: yes
Oct 17 16:31:52 systemd-resolved[7950]: vpn: Bus client set DNS server list to: 172.16.101.67, 172.16.101.68
Oct 17 16:31:52 systemd[1]: Stopping systemd-resolved.service - Network Name Resolution...
Oct 17 16:31:52 systemd[1]: systemd-resolved.service: Deactivated successfully.
Oct 17 16:31:52 systemd[1]: Stopped systemd-resolved.service - Network Name Resolution.
Oct 17 16:31:52 audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-resolved comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Oct 17 16:31:52 audit: BPF prog-id=96 op=LOAD
Oct 17 16:31:52 systemd[1]: Starting systemd-resolved.service - Network Name Resolution...
Oct 17 16:31:52 audit: BPF prog-id=0 op=UNLOAD
Oct 17 16:31:52 systemd-resolved[9242]: Positive Trust Anchors:
Oct 17 16:31:52 systemd-resolved[9242]: . IN DS 20326 8 2 e06d44b80b8f1d39a95c0b0d7c65d08458e880409bbc683457104237c7f8ec8d
Oct 17 16:31:52 systemd-resolved[9242]: Negative trust anchors: home.arpa 10.in-addr.arpa 16.172.in-addr.arpa 17.172.in-addr.arpa 18.172.in-addr.arpa 19.172.in-addr.arpa 20.172.in-addr.arpa 21.172.in-addr.arpa 22.172.in-addr.arpa 23.172.in-addr.arpa 24.172.in-addr.arpa 25.172.in-addr.arpa 26.172.in-addr.arpa 27.172.in-addr.arpa 28.172.in-addr.arpa 29.172.in-addr.arpa 30.172.in-addr.arpa 31.172.in-addr.arpa 168.192.in-addr.arpa d.f.ip6.arpa corp home internal intranet lan local private test
Oct 17 16:31:52 systemd-resolved[9242]: Using system hostname 'laptop'.
Oct 17 16:31:52 systemd[1]: Started systemd-resolved.service - Network Name Resolution.
Oct 17 16:31:52 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-resolved comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Oct 17 16:31:52 systemd-resolved[9242]: Flushed all caches.
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.5167] device (vpn): state change: activated -> unmanaged (reason 'unmanaged', sys-iface-state: 'removed')
Oct 17 16:31:52 NetworkManager[1334]: <warn> [1665995512.5176] dns-sd-resolved[169e4f4852db2fa3]: send-updates SetLinkDomains@6 failed: GDBus.Error:org.freedesktop.resolve1.NoSuchLink: Link 6 not known
Oct 17 16:31:52 gnome-shell[2291]: Removing a network device that was not added
Oct 17 16:31:52 chronyd[1269]: Source 162.159.200.123 offline
Oct 17 16:31:52 chronyd[1269]: Source 162.159.200.1 offline
Oct 17 16:31:52 chronyd[1269]: Source 78.46.102.180 offline
Oct 17 16:31:52 chronyd[1269]: Source 202.28.116.236 offline
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.9876] dhcp4 (wlp1s0): state changed new lease, address=192.168.199.159
Oct 17 16:31:52 NetworkManager[1334]: <info> [1665995512.9880] policy: set 'MyWifi' (wlp1s0) as default for IPv4 routing and DNS
Oct 17 16:31:52 avahi-daemon[1214]: Joining mDNS multicast group on interface wlp1s0.IPv4 with address 192.168.199.159.
Oct 17 16:31:52 systemd-resolved[9242]: wlp1s0: Bus client set search domain list to: telenav.cn, telenav.com, china.telenav.com, tnsoftware.telenav.com, mypna.com, skobbler.com
Oct 17 16:31:52 avahi-daemon[1214]: New relevant interface wlp1s0.IPv4 for mDNS.
Oct 17 16:31:52 avahi-daemon[1214]: Registering new address record for 192.168.199.159 on wlp1s0.IPv4.
Oct 17 16:31:52 dnsmasq[1603]: reading /etc/resolv.conf
Oct 17 16:31:52 dnsmasq[1603]: using nameserver 127.0.0.53#53
Oct 17 16:31:52 systemd-resolved[9242]: wlp1s0: Bus client set default route setting: yes
Oct 17 16:31:52 systemd-resolved[9242]: wlp1s0: Bus client set DNS server list to: 172.16.101.67, 172.16.101.68
Oct 17 16:31:55 NetworkManager[1334]: <info> [1665995515.6258] audit: op="connection-update" uuid="6b042000-0b66-452c-a857-2dda118cd4eb" name="MyWifi" args="ipv4.dns" pid=9288 uid=0 result="success"
Oct 17 16:31:55 NetworkManager[1334]: <info> [1665995515.6468] audit: op="connection-update" uuid="6b042000-0b66-452c-a857-2dda118cd4eb" name="MyWifi" pid=9292 uid=0 result="success"
Oct 17 16:31:55 NetworkManager[1334]: <info> [1665995515.6618] audit: op="device-reapply" interface="wlp1s0" ifindex=2 args="ipv4.dns" pid=9296 uid=0 result="success"
Oct 17 16:31:55 NetworkManager[1334]: <info> [1665995515.6786] dhcp4 (wlp1s0): canceled DHCP transaction
Oct 17 16:31:55 NetworkManager[1334]: <info> [1665995515.6786] dhcp4 (wlp1s0): activation: beginning transaction (timeout in 45 seconds)
Oct 17 16:31:55 NetworkManager[1334]: <info> [1665995515.6786] dhcp4 (wlp1s0): state changed no lease
Oct 17 16:31:55 avahi-daemon[1214]: Withdrawing address record for fe80::6f9c:113e:1f00:5449 on wlp1s0.
Oct 17 16:31:55 avahi-daemon[1214]: Leaving mDNS multicast group on interface wlp1s0.IPv6 with address fe80::6f9c:113e:1f00:5449.
Oct 17 16:31:55 NetworkManager[1334]: <info> [1665995515.6796] dhcp4 (wlp1s0): activation: beginning transaction (timeout in 45 seconds)
Oct 17 16:31:55 avahi-daemon[1214]: Interface wlp1s0.IPv6 no longer relevant for mDNS.
Oct 17 16:31:55 avahi-daemon[1214]: Withdrawing address record for 192.168.199.159 on wlp1s0.
Oct 17 16:31:55 avahi-daemon[1214]: Leaving mDNS multicast group on interface wlp1s0.IPv4 with address 192.168.199.159.
Oct 17 16:31:55 systemd-resolved[9242]: wlp1s0: Bus client reset search domain list.
Oct 17 16:31:55 systemd-resolved[9242]: wlp1s0: Bus client set default route setting: no
Oct 17 16:31:55 avahi-daemon[1214]: Interface wlp1s0.IPv4 no longer relevant for mDNS.
Oct 17 16:31:55 dnsmasq[1603]: reading /etc/resolv.conf
Oct 17 16:31:55 dnsmasq[1603]: using nameserver 127.0.0.53#53
Oct 17 16:31:55 avahi-daemon[1214]: Joining mDNS multicast group on interface wlp1s0.IPv6 with address fe80::6f9c:113e:1f00:5449.
Oct 17 16:31:55 avahi-daemon[1214]: New relevant interface wlp1s0.IPv6 for mDNS.
Oct 17 16:31:55 systemd-resolved[9242]: wlp1s0: Bus client reset DNS server list.
Oct 17 16:31:55 avahi-daemon[1214]: Registering new address record for fe80::6f9c:113e:1f00:5449 on wlp1s0.*.
Oct 17 16:31:55 NetworkManager[1334]: <info> [1665995515.7348] audit: op="connection-delete" uuid="340ea4a5-a726-4ea4-80d2-e67ea7fc0cf7" name="vpn" pid=9307 uid=0 result="success"
Oct 17 16:31:55 fctsched[9089]: DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus
Oct 17 16:31:55 fctsched[9089]: DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus
Oct 17 16:31:55 fctsched[9089]: DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus
Oct 17 16:31:55 fctsched[9089]: DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus
Oct 17 16:31:55 fctsched[9089]: error code -101
Oct 17 16:31:55 fctsched[9089]: Network is unreachable
Oct 17 16:31:55 fctsched[9089]: error code -101
Oct 17 16:31:55 fctsched[9089]: Network is unreachable
Oct 17 16:31:56 NetworkManager[1334]: <info> [1665995516.2558] dhcp4 (wlp1s0): state changed new lease, address=192.168.199.159
Oct 17 16:31:56 NetworkManager[1334]: <info> [1665995516.2561] policy: set 'MyWifi' (wlp1s0) as default for IPv4 routing and DNS
Oct 17 16:31:56 avahi-daemon[1214]: Joining mDNS multicast group on interface wlp1s0.IPv4 with address 192.168.199.159.
Oct 17 16:31:56 systemd-resolved[9242]: wlp1s0: Bus client set search domain list to: telenav.cn, telenav.com, china.telenav.com, tnsoftware.telenav.com, mypna.com, skobbler.com
Oct 17 16:31:56 avahi-daemon[1214]: New relevant interface wlp1s0.IPv4 for mDNS.
Oct 17 16:31:56 avahi-daemon[1214]: Registering new address record for 192.168.199.159 on wlp1s0.IPv4.
Oct 17 16:31:56 dnsmasq[1603]: reading /etc/resolv.conf
Oct 17 16:31:56 dnsmasq[1603]: using nameserver 127.0.0.53#53
Oct 17 16:31:56 systemd-resolved[9242]: wlp1s0: Bus client set default route setting: yes
Oct 17 16:31:56 systemd-resolved[9242]: wlp1s0: Bus client set DNS server list to: 192.168.199.1
Oct 17 16:31:56 systemd-resolved[9242]: Using degraded feature set UDP instead of UDP+EDNS0 for DNS server 192.168.199.1.
Oct 17 16:32:04 Fortitray.desktop[8949]: window-all-closed
Oct 17 16:32:06 systemd[1]: NetworkManager-dispatcher.service: Deactivated successfully.
The Forticlient VPN is installed via official RPM with no dependencies missing. The fact that it's working with LAN but not Wifi looks like an incompatibility issue with NetworkManager shipped with Fedora 36.
Thanks in advance!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.