Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mariano_lavia
New Contributor II

FortiClient VPN Android 7.4.3 not connecting to FortiGate after upgrading to 7.6.5

All my Android clients running FortiClient VPN 7.4.3 (ipsec/ikev1 + psk + xauth connection type) are unable to connect to my FortiGate after upgrading it's OS from 7.6.4 to 7.6.5.

The client fails with "could not estabilish session on ipsec deamon" message.

 

Using "diag debug app ike -1", I can see that phase 1 is completed, user authenticated, tunnel is up (visible on firewall ipsec monitor, but 0 bytes), but phase 2 is never completed.

 

After "negotiation result" is ok and a few lines more, it says:

 

ike V=root:0:VPN-IPSEC_6: tunnel up event assigned address 10.201.109.168
ike V=root:0:VPN-IPSEC_6: EMS: FCT UID not ready

 

then the firewall starts a loop of "retransmission" (R-U-THERE/R-U-THERE-ACK), until the client quits.
Nothing was changed on the firewall except the OS update.
Testing with other clients (not FortiClient) everything works fine.
Any idea on the cause/solution?

2 REPLIES 2
HarryTran
Staff
Staff
mariano_lavia

Hi Harry,

is true that we had DH 5, 14 enabled on the server side, but only DH 14 is enabled on the client. The SA negotiation is completed in my logs, and a proposal is chosen.
Also, if I understand it correctly, the OS change is only about default values, but it doesn't mean you can't select it manually. There is no visible mismatch in our settings.
Thanks anyway for your suggestions.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors