Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
damianhlozano
Contributor II

FortiClient IPsec VPN does not connect sometimes

Hello team!!

 

I hope you are doing well!!

We have 2 Fortigates 100F in HA with many IPsec VPNs for FortiClient users.

Just one user has a problem to connect from his house.  When he use another internet connection in the same computer this works fine but with his own ISP sometime does it fails (Sometimes work also)

When this fails, I can see the following logs on Fortigate:

 

date=2025-09-11 time=12:38:58 eventtime=1757605138121774900 tz="-0300" logid="0101037134" type="event" subtype="vpn" level="notice" vd="root" logdesc="IPsec phase 1 SA deleted" msg="delete IPsec phase 1 SA" action="delete_phase1_sa" remip=RemoteIP locip=LocalIP remport=18052 locport=4500 outintf="port9" cookies="b77cf798b4edb960/b7f28e5eae0677b7" user="1011" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="IPsec-IT-W3" fctuid="N/A" advpnsc=0
date=2025-09-11 time=12:38:38 eventtime=1757605118948074500 tz="-0300" logid="0101037127" type="event" subtype="vpn" level="notice" vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=RemoteIP locip=LocalIP remport=18102 locport=500 outintf="port9" srccountry="Argentina" cookies="b77cf798b4edb960/b7f28e5eae0677b7" user="1011" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="IPsec-IT-W3" status="success" init="remote" mode="aggressive" dir="outbound" stage=1 role="responder" result="OK" fctuid="N/A" advpnsc=0
date=2025-09-11 time=12:38:38 eventtime=1757605118977300400 tz="-0300" logid="0101037127" type="event" subtype="vpn" level="notice" vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=RemoteIP locip=LocalIP remport=18102 locport=4500 outintf="port9" srccountry="Argentina" cookies="b77cf798b4edb960/b7f28e5eae0677b7" user="1011" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="IPsec-IT-W3" status="success" init="remote" mode="aggressive" dir="inbound" stage=2 role="responder" result="DONE" fctuid="N/A" advpnsc=0
date=2025-09-11 time=12:38:38 eventtime=1757605118977889960 tz="-0300" logid="0101037127" type="event" subtype="vpn" level="notice" vd="root" logdesc="Progress IPsec phase 1" msg="progress IPsec phase 1" action="negotiate" remip=RemoteIP locip=LocalIP remport=18052 locport=4500 outintf="port9" srccountry="Argentina" cookies="b77cf798b4edb960/b7f28e5eae0677b7" user="1011" group="N/A" useralt="N/A" xauthuser="N/A" xauthgroup="N/A" assignip=N/A vpntunnel="IPsec-IT-W3" status="success" init="local" mode="xauth" dir="outbound" stage=1 role="initiator" result="OK" fctuid="N/A" advpnsc=0

 

If I ping the Fortigate IP from the computer, I get answers, so this is not a route issue.

I thought maybe this is another issue with his ISP, but I dont think so, because sometimes does this work.

Do you have any idea?

 

Thanks in advance.

Regards,

Damián

Damián Lozano
Damián Lozano
1 Solution
AEK
SuperUser
SuperUser

Hi Damian

According to your description I suspect the ISP, even if the issue is intermittent.

You should contact the ISP to ask if there is any limitation or restriction with IPsec.

AEK

View solution in original post

AEK
4 REPLIES 4
AEK
SuperUser
SuperUser

Hi Damian

According to your description I suspect the ISP, even if the issue is intermittent.

You should contact the ISP to ask if there is any limitation or restriction with IPsec.

AEK
AEK
damianhlozano

Thank you AEK!

There is a cloud EMS providing the settings to clients, but although I know the connection is between each client and the Fortigate (VPN Server), idk if there is any check performed by the EMS, for example, IP reputation.  Is this possible?

Does Fortigate or FortiClient EMS checks for IP reputation or something related?

I configured the EMS, so I know this is not a security posture tag, or at least this is not related with the security posture tags that I selected for the VPN (Computers must have an OS not so old, and must have an antivirus updated and running)

 

Regards,

Damián

Damián Lozano
Damián Lozano
AEK
SuperUser
SuperUser

Hi Damian

Yes it is possible that your FortiGate is checking IP reputation but this is not the default behavior. It only does it if a policy is configured to do so.

If you have access to the FGT the good thimg to do is to run packet sniffer on FGT while you try connect VPN. If the packets are not reaching FGT the it is definitely due to your ISP.

AEK
AEK
damianhlozano

Thank you AEK!!

We restarted the router of the ISP (Client side) and the issue seems to be solved.

I never suspected of the Fortigates settings, but my boss wanted to be sure before ask anything to the user.

 

Thanks!

Regards,

Damián

Damián Lozano
Damián Lozano
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors