Hi, I am running FortiOS 7.4.7 on a FortiGate-60F and am trying to migrate from SSLVPN to IPsec VPN.
I've managed to configure IPsec (IKEv2) dial-up to work fine, but I notice that when I set the mode to IPSec over TCP, FortiClient (v7.4.3) does not connect and times out. UDP mode works perfectly fine.
I also notice that TCP 4500 is not one of the local-in policies on the firewall.
Does a local-in policy need to be configured for this to work? Has anyone had any experience with this?
Thank you!
Having the same issues using IPsec over TCP. Its working for most clients except some. Have narrowed it down to the clients that aren't working are trying from laptops that are tethering off their phones, with the phones being on the Vodafone network. In Australia, Telstra seems to be working, but Vodafone not. Saw somewhere to adjust the TCP MSS sizes as below, but not had any luck yet.
config firewall policy
edit 1
set tcp-mss-sender 1360
set tcp-mss-receiver 1360
next
end
User | Count |
---|---|
2554 | |
1356 | |
795 | |
647 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.