Dear All,
Issue : Auto-connect VPN is not working
Configuration: we are have enabled auto-connect in both Fortigate and Forticlient EMS
After create ticket with Fortinet Team , i got below reply
2023-08-24 15:24:35.8535432] [5900:18048] [sslvpndaemon 497 debug] FortiSslvpn: 18048: failed to add route for 00000000:00000000, error code:5010
[2023-08-24 15:24:35.8538146] [5900:18048] [sslvpndaemon 497 debug] FortiSslvpn: 18048: DoModifyIpForwardEntryIPv4:467 Correct Parameter, dual_stack:0, dwTunnelAddr:111.93.12.210, dwFGroute:192.168.81.55, dwPppIp:10.0.96.12
[2023-08-24 15:24:35.8574022] [5900:18048] [sslvpndaemon 497 debug] FortiSslvpn: 18048: DoModifyIpForwardEntryIPv4:500 pIpRouteTab->table[i].dwForwardNextHop:10.0.96.13
;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL:
Line 133211: [2023-08-24 15:24:39.9143758] [transctrl 912] ipv4 addr: 10.0.22.22 (0x0A001616), domain_name = corp.hdworks.in
Line 133432: [2023-08-24 15:24:40.6678654] [transctrl 912] ipv4 addr: 10.0.22.22 (0x0A001616), domain_name = DCHYD.corp.hdworks.in
2023-08-24 15:24:41.4972610] [fortitcs] ServeDNS: end
[2023-08-24 15:24:43.7188268] [fortitcs error] Failed to query DNS (%v): %v10.0.22.22dns: no secrets defined
[2023-08-24 15:24:43.7189816] [fortitcs] (TCP-DNS):
;; opcode: QUERY, status: NOERROR, id: 8471
Line 116171: [2023-08-24 15:24:57.4497957] [6672:7700] [FortiVPN 53 debug] fortivpn::StateMachine::AddEvent type=18 (TunnelConnectFailed)
Line 116176: [2023-08-24 15:24:57.5109584] [6672:6676] [FortiVPN 326 debug] Got event: 18 "TunnelConnectFailed"
Line 116177: [2023-08-24 15:24:57.5109813] [6672:6676] [FortiVPN 105 debug] In state: TunnelConnectFailed
Failed to add route: Failed to add route: failed to add route for 00000000:00000000, error code:5010
- This suggests that there was an issue with adding a route to the routing table.
Failed to query DNS: Failed to query DNS: Failed to query DNS (%v): %v10.0.22.22dns: no secrets defined - This suggests that there might be a DNS issue. The system couldn't query the DNS, and it mentions "no secrets defined," which might indicate a configuration issue.
Can you please verify if the routing table and rules are correctly configured in both FortiGate and Forti Client EMS. Make sure that the DNS settings are correctly configured. Ensure that there are no firewall rules blocking the VPN connection.
- You can refer this document: https://community.fortinet.com/t5/FortiClient/Technical-Tip-Explanation-of-the-failed-to-add-route-e....
-- For DNS troubleshooting you can refer this document: https://community.fortinet.com/t5/FortiGate/Technical-Tip-DNS-troubleshooting/ta-p/197982
-- Also verify the VPN configuration.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.