- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiClient VPN Connect/Immediate Disconnect
I have seen a few posts with the same title but nobody seems to have found a solution yet. Has anyone found a working solution to the issue where FortiClient will connect to VPN then immediately disconnect? We are using FortiClient with EMS, and if the user has auto retry checked it will repeatedly try to reconnect and fail. Sometimes I can force it to start working again by shutting down the Forticlient app and restarting the computer but I can't find any useful information in logs or debug info. FG is on 7.4.2, FC client is 7.2.3, and EMS 7.2.2 (which I plan to update to 7.2.4 sometime this week). If you have any solutions I appreciate it!
- Labels:
-
FortiClient
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@rlewcosa
Can you please check if there is any other software installed on your machine that might conflict with FortiClient? Some other VPN solution?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can confirm there is no other VPN software, we had previously been using the free Forticlient before upgrading to the full ZTNA version with EMS/FortiAuth. This is occurring however on both devices that had been upgraded and new, fresh Windows installs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you see it successfully establish (screen changes, gives you an IP), or does it stop at a specific percentage (98%)? Are you using SAML?
In cases like these, I like to disable IPv6 on both your physical Ethernet adaptor, and the Fortinet SSLVPN adaptor as well.
Created on 03-11-2024 10:45 AM Edited on 03-11-2024 10:46 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It does successfully establish - User will hit connect, it reaches 48% and prompts for their token key which they enter, then pauses for a second at 98%. After that it will say connected successfully followed immediately by a disconnected message. When it does that they usually are not successful trying to connect again, they have to shutdown the client and reboot. I'll try disabling the IPv6 and see what happens.
I am wondering if latency could be causing it? The devices are laptops in police cars running almost 100% off of cellular. While we generally have good reception and average around 50mbps off LTE, I'm wondering if any bit of latency causes issues with the connection process. I do have an email out with our account rep so if I find out anything useful I'll update the thread.
**Edit: I should add, when viewing the authentication logs in FortiAuthenticator for the affected user, it will show multiple "login successful, awaiting token" and "token successful" entries back to back, no error messages or failures.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hmmm, I would also try with and without DTLS if you know latency is gonna be high. I have had similar cases where DTLS would refuse to work, and others where it would only work with DTLS on.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'll try that and see what happens. DTLS is currently off but I'll enable it and listen for any end users having problems.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any updates on this? We are having similar issues with some clients connecting to SSL VPN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you the same user as seen previously on this thread? If not, a good place to start would be to look at the other suggestions and report the results back.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry I didn't get to update the thread. It did seem like DTLS helped. For the most part, users are able to connect without issue. On occasion they'll run into this problem again, but if they just shut down the FortiClient app and reopen it, they can log in again normally. It must get stuck on something that shutting down the app fixes.