Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ryanswj
New Contributor

FortiClient Remote Access IPsec-over-TCP not working

Hi, I am running FortiOS 7.4.7 on a FortiGate-60F and am trying to migrate from SSLVPN to IPsec VPN.

 

I've managed to configure IPsec (IKEv2) dial-up to work fine, but I notice that when I set the mode to IPSec over TCP, FortiClient (v7.4.3) does not connect and times out. UDP mode works perfectly fine.

 

I also notice that TCP 4500 is not one of the local-in policies on the firewall.

 

Does a local-in policy need to be configured for this to work? Has anyone had any experience with this?

 

Thank you!

 

41 REPLIES 41
mrsimon007
New Contributor II

Ensure that TCP port 4500 is included in your local-in policies. If it is not, you may need to create a rule to allow traffic on this port.

mbqc
New Contributor

Did you manage to get this working? We are facing the exact same issue with a 90G.

FC 7.4.3.1790, FortiOS 7.4.7

ryanswj
New Contributor

No, I have not. I think it may be a bug in 7.4.7, so am waiting for the next version to be released. Let me know if you make any headway.

MZBZ
Staff
Staff

1. FreeVPN FortiClient does not support IKEv2 over TCP. It works with the EMS connected version!

2. Both FortiOS and FortiClient will get a major enhancement in the next release (FortiOS 7.4.8 and FortiClient 7.4.4) that will address your issues...

M. B.
ryanswj
New Contributor

Oh... that would explain everything! Do you know ETA of FOS 7.4.8 or FC 7.4.4 and whether both are required to make this work or just the FC upgrade will do?

MZBZ

The issue on FortiOS side is different in nature from the FortiClient side. Troubleshooting this problem is hard as you do not know which side is causing the unexpected behavior. You may confirm the fix from Release Notes when published.

M. B.
Toshi_Esumi

@MZBZ  Well, I'm using FortiClient VPN 7.4.2. And it's working as long as I enabled EAP "set eap enable" via CLI. And, FortiOS side is 7.4.6.

Toshi

MZBZ

Depends on the setup and history of FortiOS upgrades! It does not affect all setups.

M. B.
Toshi_Esumi

That means your statement No.1 "FreeVPN FortiClient does not support IKEv2 over TCP." is, at least, not always apply since it works in some cases.
That's my point.

Toshi

MZBZ

IKEv2 over TCP is not officially supported or provided with the Free VPN Client.

M. B.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors