Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ryanswj
New Contributor

FortiClient Remote Access IPsec-over-TCP not working

Hi, I am running FortiOS 7.4.7 on a FortiGate-60F and am trying to migrate from SSLVPN to IPsec VPN.

 

I've managed to configure IPsec (IKEv2) dial-up to work fine, but I notice that when I set the mode to IPSec over TCP, FortiClient (v7.4.3) does not connect and times out. UDP mode works perfectly fine.

 

I also notice that TCP 4500 is not one of the local-in policies on the firewall.

 

Does a local-in policy need to be configured for this to work? Has anyone had any experience with this?

 

Thank you!

 

41 REPLIES 41
Toshi_Esumi

FCT743IPsec.png

 

Ok, probably I mis-took your meaning of the word "not supported". The entire FortiClient VPN itself is "not supported" version of FortiClient any way.
At least above is my setting with 7.4.2 (now upgraded to 7.4.3) and working with FGT 7.4.7 IKEv2 config. I ran IKE debugging/Sniffing to confirm it's indeed connected over TCP.

Toshi

MZBZ

We have two FortiClient versions: FortiClient VPN only (standalone) and FortiClient which connects to EMS. IKEv2 over TCP is officially supported with the latter one.

FortiClient standalone and licensed version feature comparison | FortiClient 7.4.3 | Fortinet Docume...

M. B.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors