Hi All,
We are experiencing an issue with the forticlient VPN client on MacOS 15.5
We are currently planning our roll out of remote access via IPsec and moving away from SSL VPNs,
The issue we are having is that after a device cold start/reboot, the initial attempt to connect to the remote access VPN via IPsec always fails and gives an "Connection was terminated unexpectedly" error.
Trying it immediately again afterwards, it still fails.
The current workaround is to connect to the same remote VPN endpoint but via SSL VPN, and then trying the IPsec once more; however, this does not always seem to work.
Another workaround seems to be waiting 5-10 minutes, and trying the IPsec connection seems to work.
Once successfully connected via the IPsec VPN, it continues to work until the client device is rebooted/shut down.
Looking through the Forticlient debug logs, we are getting an "IPsec error -104"; however, when running an authentication debug on the FortiGate, I can see we are successfully authenticating via LDAP + Duo MFA.
When using the same login details to the same LDAP server but via SSL VPN, it works and authenticates successfully 100% of the time.
Because of this, I do not trust that the -104 error is real.
When running Wireshark captures, I can also see the FortiClient app begins to initiate the phase 1 process, but when the FortiGate firewall responds, the Forticlient application does not continue on to the quick mode process and gets stuck sending NAT-Keepalive messages to the FortiGate.
The issues seem to have started after upgrading the macOS version to 15.5.
We are not experiencing this issue with older versions of MacOS (ie. macOS 12.7.6)
The issue is also affecting versions of Forticlient VPN, including 7.4.0, 7.4.1, 7.4.2 & the current version 7.4.3
This issue is limiting our rollout of the IPsec remote access VPN.
if anyone has experienced a similar issue, I would greatly appreciate any assistance.
Hello Sohonet,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi Jean-Philippe,
That would be great thank you.
This issue is really hampering the rollout of our IPsec remote access VPN so hopefully we can find a solutions asap :)
kind regards
Ryan Bates
Sohonet
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello again Sohonet,
I found this solution. Can you tell me if it helps, please?
It seems like you're encountering a challenging issue with the FortiClient VPN on macOS 15.5, particularly with the IPsec connection after a reboot. Here are some troubleshooting steps and considerations that might help you address this problem:
Check for Updates: Ensure that both FortiClient and macOS are updated to the latest versions. Sometimes, compatibility issues can arise from outdated software.
Reinstall FortiClient: Uninstalling and then reinstalling FortiClient may resolve any corruption or misconfiguration that occurred during the upgrade.
Network Configuration: Verify that there are no changes in network settings or firewall rules that could be affecting the IPsec connection. Ensure that the necessary ports for IPsec (UDP 500 and 4500) are open and not being blocked.
Review Logs: Since you've already looked at the debug logs, continue to monitor them for any additional errors that might provide more context. Pay close attention to logs around the time of the connection attempts.
NAT Keepalive Settings: Since you've noticed the client is stuck sending NAT-Keepalive messages, check the NAT Keepalive settings on both the FortiClient and the FortiGate. Adjusting these settings might help in establishing a more stable connection.
Test with Different Configurations: If possible, test the IPsec connection with different configurations or profiles to see if there's a specific setting causing the issue.
Compatibility Mode: If the issue began after upgrading macOS, consider running FortiClient in compatibility mode if that option is available.
Contact Support: Since this issue seems to be specific to the combination of macOS 15.5 and FortiClient, reaching out to Fortinet support may yield more tailored assistance or insights into known issues.
Community Forums: Check Fortinet community forums or user groups for similar issues. Other users may have encountered and resolved this problem.
If the issue persists, documenting all your findings and steps taken will be helpful when seeking further support from Fortinet or your IT department.
Hi Jean-Philippe
Thank you for getting back to me.
Thanks for all these infos. As I am not a TAC engineer, I cannot go further with you but I asked help and someone might come back to help you :)
Hi Jean-Philippe,
no worries, thank you for passing it on and for you help so far.
kind regards
Ryan Bates
Sohonet.
Hello Sohonet,
Based on the information provided, the issue appears to match an existing case that has already been reported to our engineering team and is currently under investigation.
Could you please confirm whether the affected FortiClients are managed via EMS?
If so, Please report the issue to TAC and attach the full Diagnostic Tool output .
BR
Hi Kumar_B
We are not managing our Forticlient's via EMS and only using the stand-alone software.
kind reagrds
Ryan Bates
Sohonet.
User | Count |
---|---|
2428 | |
1303 | |
778 | |
556 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.