Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ryanswj
New Contributor III

FortiClient Remote Access IPsec-over-TCP not working

Hi, I am running FortiOS 7.4.7 on a FortiGate-60F and am trying to migrate from SSLVPN to IPsec VPN.

 

I've managed to configure IPsec (IKEv2) dial-up to work fine, but I notice that when I set the mode to IPSec over TCP, FortiClient (v7.4.3) does not connect and times out. UDP mode works perfectly fine.

 

I also notice that TCP 4500 is not one of the local-in policies on the firewall.

 

Does a local-in policy need to be configured for this to work? Has anyone had any experience with this?

 

Thank you!

 

60 REPLIES 60
Leo-
New Contributor

Having the same issues using IPsec over TCP. Its working for most clients except some. Have narrowed it down to the clients that aren't working are trying from laptops that are tethering off their phones, with the phones being on the Vodafone network. In Australia, Telstra seems to be working, but Vodafone not. Saw somewhere to adjust the TCP MSS sizes as below, but not had any luck yet.

 

config firewall policy
            edit 1
                set tcp-mss-sender 1360
                set tcp-mss-receiver 1360
            next
        end

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors